Live data from Hacker News

Tell HN: Somebody implemented something I wrote a blog about

news.ycombinator.com

211–220 of 253 posts

Re: Tell HN: Somebody implemented something I wrote a blog about

#211

Years back, every web browser's built-in password manager locked up the page when submitting a login form, waiting for the user to answer "do you want to save this password?" before proceeding. I thought that was silly: how do I know if I want to save the password before I've seen whether it's correct? Which I can't see until the form is submitted. At the time I was using Opera, so I wrote in to their customer suppor…

Oh, that's so cool! :-) Could you please write to Whatsapp or Telegram and ask them not to delete the EXIF information from shared images on their platform? I understand that they compress images so they don't take too long to transmit and load, but I think there's a big group of their users (especially for Whatsapp) that use their platform to share family pictures. For this purpose, having the EXIF date (if it's ava…

People would doxx the hell out of themselves without knowing it all the time if you did that.

Re: Tell HN: Somebody implemented something I wrote a blog about

#212

Earlier quoted context omitted.

This is not a huge deal in practice and can be a good honeypot/alarm system. Most services today have fairly low "lockout" + "notify" thresholds on wrong passwords so brute force spraying passwords is already out of the question. Now, if someone fails the password check, clearly the user's current password is still secure so leaking that the attempted password was wrong to an attacker is not particularly helpful to t…

> Now, if someone fails the password check, clearly the user's current password is still secure so leaking that the attempted password was wrong to an attacker is not particularly helpful to them. Maybe I misunderstand your post, but I think the parent comment is talking about leaking whether a password is correct and not whether it's wrong . (If I did misread your comment, apologies in advance and disregard the rest…

But the moment the attacker knows the password is correct, you/the platform would also know the password is compromised assuming they cannot get past 2FA. There is an extremely limited amount of situations that end up with "passed password authentication but failed 2FA" and all the platform needs to tell them apart is a simple "Hmm, were you attempting to login?" email or notification.

The leak of the password's correctness here is ultimately not problematic as it acts as a tripwire and a surprise for the attacker. In fact the platform can take action on the user's behalf and lock logins with that password until the user confirms it was them trying to login via a separate channel (if you used Google 2FA this is what they do). It also protects accounts without 2FA because it becomes risky for the attacker to just try a password list they find. Maybe they're lucky and get in, or maybe the account has 2FA and you've just burned the password by trying it and alerting the user/platform about the compromise.

If it were the other way around with 2FA first, you would have no way of knowing your password is compromised somewhere. Even if the attacker knew the right password, the would not attempt to login unless they defeated the 2FA. Now you have no early warning system, and it becomes all-or-nothing: attacker get full access or they wait silently.

To sum it up: The login is no weaker if you put 2FA after password auth (same amount of compromises needed to get in). 2FA after password can leak password validity information for a short duration of time (on the scale of 15mins), but it also sets in motion an alarm that invalidates that password when an attack is attempted. 2FA after password also provides a tiny bit of extra protection to non-2FA accounts by letting them hide among the 2FA ones.

(Also, the original purpose of 2FA after password is to cut down costs for the platform back when SMS 2FA was the only 2FA. This is largely irrelevant today with TOTP and FIDO2 relegating SMS based authentication as the least secure option.)

Re: Tell HN: Somebody implemented something I wrote a blog about

#214

Earlier quoted context omitted.

I actually had someone take one of my personal iOS apps from GitHub ( https://github.com/wcochran/calfoo ) and submit it to the app store as if it was theirs. Someone else told me -- I was gobsmacked that someone was so brazen. Oh well, I didn't license it. It had special features that only mattered to me (and would be inappropriate for general use).

Just fyi, if something is unlicensed, then other people can only use it under fair use. You’re the copyright holder automatically upon publishing and retain all rights. If you intend to let people do anything, then you need to explicitly put it in the public domain or use an appropriate license. It’s very unlikely they can legally do what you’re describing… but it’s up to you to enforce it.

Most people wouldn't enforce it.

Thousands in legal fees, chasing someone across different timezones and the sheer amount of work isn't worth it unless it's a legit business.

Copyright laws really fail for those without money.

Re: Tell HN: Somebody implemented something I wrote a blog about

#216
post #98

Earlier quoted context omitted.

It’s like that Teams pop up that informs you that a colleague started a meeting, the one that always disappears after you finish typing your sentence and start to move your mouse towards it.

you can click it right away, finish your sentence, then click again to join the meeting once you're done :]

Ha! Great tip indeed!

Re: Tell HN: Somebody implemented something I wrote a blog about

#217

Earlier quoted context omitted.

Yeah, I get why it wouldn't be. I just have a peculiar way to organize my music. I know I can do that, it just doesn't sync when I change another list, which breaks everything.

You can use the Spotify Smart Playlists feature to do this. I used to do something similar before giving up. It's clunky, but it works. You basically set it to pull all new songs from the feeder playlists into the accumulation playlists, every night.

I can't find an official feature, you mean this?

http://smarterplaylists.playlistmachinery.com/

Re: Tell HN: Somebody implemented something I wrote a blog about

#218

Earlier quoted context omitted.

Something I really miss from Opera is that the content of every page you visited was saved and stored for search! This helped me so often to find pages that I had visited, and remembered a few words from, but didn't bookmark or save otherwise. No idea why browsers today did not copy this feature.

Web browsers are strange. They are sophisticated pieces of engineering, but they refuse to implement the lowest hanging fruit features UX wise.

A cynical take is that they purposely hold back bookmarks/offline-search so that you use their web search engine instead.

Re: Tell HN: Somebody implemented something I wrote a blog about

#219
post #32

OWASP actually includes this suggestion in their guidance for implementing MFA: https://cheatsheetseries.owasp.org/cheatsheets/Multifactor_A... > When a user enters their password, but fails to authenticate using a second factor...: > ... > Notify the user of the failed login attempt, and encourage them to change their password if they don't recognize it. > The notification should include the time, browser and geogra…

Yeah I thought it weird that you only get an e-mail that someone logged in under a new account - passing the 2fa. But they should send one after correct username / password too.

I don't mind getting an e-mail as another form of 2fa, but that has its own issues.

Re: Tell HN: Somebody implemented something I wrote a blog about

#220

Earlier quoted context omitted.

Oh, that's so cool! :-) Could you please write to Whatsapp or Telegram and ask them not to delete the EXIF information from shared images on their platform? I understand that they compress images so they don't take too long to transmit and load, but I think there's a big group of their users (especially for Whatsapp) that use their platform to share family pictures. For this purpose, having the EXIF date (if it's ava…

I think the EXIF data is removed because, for the vast majority of people that don't think to remove it, it's a safety risk. Posting a picture of your house? Your kid arriving at their first day of school? Some other location you'd rather a bad person not have info on? Most people don't think to remove that data before posting (and sometimes post directly from their phone camera?)... removing that data removes a lot…

We could always strip the location information (or any other identifying data like camera/phone model). But I can't see how having the date information attached to the image could be a safety risk. Especially when that information is already available within the app. The issue is that the app's UI is cumbersome to provide both pieces of information at the same time for a set of images.
Post reply on HN