Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

211–220 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#211

Why do Facebook and Twitter and etc. permit posting of airline QR codes and credit card photos without a safety warning and an option to safely blur out the sensitive bits?

Why do they permit it...? Because they aren't our parents and shouldn't be responsible for all the stupid shit that users could do. The real question: Perhaps we can politely convince these services to display safety warnings & blur the sensitive bits? Want to be proactive about it: Help develop a plug & play library for services to use to accomplish this feat.

> aren't our parents ...

Doesn't seem to stop them from trying to find naughty photos and block them.

https://www.geek.com/apps/is-it-nude-algorithm-wants-to-find...

Re: Post a boarding pass on Facebook, get your account stolen

#212
post #146

Earlier quoted context omitted.

How are they supposed to know you use one?

Not that they can really know, but most I've seen is that they disable pasting anything into the website, effectively making banking super slow for us with password managers and long passwords. Fortunately, my bank doesn't disable pasting (Banc Sabadell in Spain). Instead the password is restricted to maximum 6 numbers for login. Yay banks!

In Firefox, at least, there is an about:config option to turn off the ability of webpages to disable paste. Flip that setting and managers work again on those pages.

Re: Post a boarding pass on Facebook, get your account stolen

#214
post #146

Earlier quoted context omitted.

Not that they can really know, but most I've seen is that they disable pasting anything into the website, effectively making banking super slow for us with password managers and long passwords. Fortunately, my bank doesn't disable pasting (Banc Sabadell in Spain). Instead the password is restricted to maximum 6 numbers for login. Yay banks!

6 characters? Let me guess, were there restrictions on character space and case? One place I had an account has a password input that restricts all of those, so it's like an 8-10 character string of all capital letters. I don't understand it at all.

This is often an externally visible code smell that implies plaintext storage of passwords in a char(10) (or whatever the max length is) db column.

Re: Post a boarding pass on Facebook, get your account stolen

#215

Earlier quoted context omitted.

I believe the general recommendation I saw was to type something in lines of "never accept this answer - it's probably someone trying to impersonate me | 2DXSDGREDV@#!" (although it's probably hard to do so if the maximum acceptable length is too short)

This is how you get engraved plaques, or birthday cakes, with the message NO MESSAGE JUST LEAVE IT BLANK on them.

Haha, true.

Still, if that helps in one case per thousand, it's still better than none.

Re: Post a boarding pass on Facebook, get your account stolen

#216

Earlier quoted context omitted.

> My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager The problem with this is that the "security" question will often be asked over the phone. At this point an answer of "Oh I just mash the keyboard for those" is probably going to get an attacker access to your account..

One solution would be to randomly generate security answers with human readable words. Diceware does this. You can use a dice, or you can use an open source tool like this one: https://www.rempe.us/diceware/#eff https://en.wikipedia.org/wiki/Diceware

[deleted]

Re: Post a boarding pass on Facebook, get your account stolen

#217

Earlier quoted context omitted.

You don't have to say "oh I just mash the keyboard for those", you can say "it's weird, bear with me" and read it out from your password manager.

I do exactly this. About 4-5 characters in the support person interrupts me with "yeah, whatever". The entire security question situation makes me incredibly pessimistic that we will ever get good security. The idea of security questions is so mind numbingly stupid to me yet it's widely used. One would have thought that after the Sarah Palin hack years ago everyone would have realised that but it seems like nobody di…

Four to five characters is probably enough for their threat model though?

The only way I can think of that somebody could steal only the first few characters of your security answer is by looking over your shoulder at a very unfortunate time. That seems unlikely, and most of the questions they use are predictable from the first few characters when answered genuinely anyway (surnames, car names, streets and towns).

Re: Post a boarding pass on Facebook, get your account stolen

#218

Earlier quoted context omitted.

How would the attacker know that you mashed the keyboard when answering 'What high school did you go to?' ?

Most likely from a "helpful" CS agent offering up the hint above. "It's really weird" or "I've never seen that one before" or just an odd chuckle. Anything an attacker could use to gain an advantage will be used to compromise you eventually.

Or because you posted about it on HN...

Re: Post a boarding pass on Facebook, get your account stolen

#219
post #207

Earlier quoted context omitted.

One solution would be to randomly generate security answers with human readable words. Diceware does this. You can use a dice, or you can use an open source tool like this one: https://www.rempe.us/diceware/#eff https://en.wikipedia.org/wiki/Diceware

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable.

These are supposed to be the very last line of defense for security, including if lose your password manager. As an exaggerated analogy, imagine that being unable to answer these questions meant your house, car, and life savings are taken from you. That is how important these answers are, except you're "only" losing one online account at a time.

Of course, it's terrible to use personal information that can be known to 3rd parties. It's also bad to reuse the same answers across multiple companies, as a compromise at one means you're at risk everywhere. The reason behind why security questions exist is a good one, but they don't offer enough security when used as intended (memorable, non-random data). The problem is there is currently no better alternative, short of requiring you to tie your legal identity to every account, and having to show up in person with photo ID to regain control of an account you've lost access to.

Anything relying on tech (like a password manager) is a bad idea for the general public. The average person does not have multiple off-site backups to guarantee that the information is physically impossible to lose.

Re: Post a boarding pass on Facebook, get your account stolen

#220

Earlier quoted context omitted.

This is how you get engraved plaques, or birthday cakes, with the message NO MESSAGE JUST LEAVE IT BLANK on them.

Haha, true. Still, if that helps in one case per thousand, it's still better than none.

We offer fast and easy loan to everyone without any stress. Blacklisted are also welcome

Hello dear loan seekers, are you a business man or woman, Are you tired of seeking loans or are you in any financial mess,have you been turned down constantly By your banks and other financial institutions,We offer any form of loan to individuals and corporate bodies at low interest rate of 2%. If you are interested in taking a loan,feel free to contact us today,we promise to offer you the best services ever. Just give us a try,because a trial will convince you . What are your Financial needs? Do you need a business loan? Do you need a personal loan? Do you want to buy a car or a house? Do you want to refinance?Do you need a mortgage loan? Do you need a huge capital to start off your business proposal or expansion? Do you need to pay medical bills, Have you lost hope and you think there is no way out, and your financial burdens still persists? Contact us with our valid emails: (anthonysa.agentloan@gmail.com) You can also call us or send message through whatssap : +12679065312 Thanks and look forward to your prompt reply Please email us at: (anthonysa.agentloan@gmail.com) for an application form.

Post reply on HN