Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

251–260 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#251
post #207

Earlier quoted context omitted.

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

That might have been the theory of security questions early on. But by now I'm sure I've filled out security questions dozens of times. Whatever the intent, from my perspective as a user, they're in the "speed bump" category of security.

For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying via internet form is pretty easy. Walking into a building with 100 cops bearing fake ID is a whole different level.

Re: Post a boarding pass on Facebook, get your account stolen

#252
post #245

Earlier quoted context omitted.

Ha... I just checked my Other Dougs folder. On Aug 4, I got an email from myidentityassist.com saying that "I" reported a case of identity theft, and that "my" Royal Bank of Canada credit card has been blocked from further use. Then on Aug 5 I got an email confirming an order from a Pizza Hut in Kingston ON, Canada, using the same variation on my email address. This is one of my repeat-offenders. I see a lot of email…

Have you tried calling him up? http://www.canada411.ca/search/?stype=si&what=Doug+Webb&wher...

Wow, an official, functional, online phonebook with addresses? I didn't know those still existed. Crazy Canadians. Thanks, I may give that a try.

Re: Post a boarding pass on Facebook, get your account stolen

#253
post #61

Earlier quoted context omitted.

And really this has nothing to do with Facebook at all, it's not a good title.

Eh, Instagram is owned by Facebook, so I gave that a pass.

I thought the point was about the risks of posting images of boarding passes on the internet. Where they happen to be posted seems irrelevant to me, but whatever.

Re: Post a boarding pass on Facebook, get your account stolen

#254
post #141

Earlier quoted context omitted.

Sounds like a "correct battery horse staple" would fit the bill

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

Median novel has some 65k words. Take all (consecutive) quotes of 2 to 24 words, and you have some 1.5m phrases. Take the top 666k books (apparently there've been about 130m titles been published in total, about 5m in the Amazon Kindle store), and you're at about 1e12 phrases, or 40 bits of entropy, or worse than a password with 7 random letters/digits/symbols.

You could probably improve on it considerably by selecting fewer books, and only taking quotes starting at some punctuation mark.

For a naturally throttled attack like here (on the phone) that's fine, but for an offline attack (where the attacker has access to the password hash) that can be cracked within days.

Re: Post a boarding pass on Facebook, get your account stolen

#255
post #207

Earlier quoted context omitted.

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

> The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory

And it's a shame to lose that feature, but they compromise your security so terribly that you're far better off not using them.

> it is possible to lose them - and that is unacceptable

Ten steps forward, two steps back. I find that acceptable.

Re: Post a boarding pass on Facebook, get your account stolen

#256
post #162

Earlier quoted context omitted.

Necronomicon quote? Nice. This has me thinking about what I can do to make my security answers to security questions untethered from PII. A book quote is a really good idea.

Close! Cryptonomicon. I'm guessing that having every book loaded into a password cracking database, subdivided and indexed by each leading phrase word, is still computationally infeasible for non-government actors.

See my comment above - unless I'm mistaken, taking all 2 to 24 word quotes from the most popular 1 million novels gives you about 40 bits of entropy (less than a password of length 7), and can easily be stored on one hard drive. In other words, feasible even for some script kiddie in mom's basement.

Re: Post a boarding pass on Facebook, get your account stolen

#257
post #33

Earlier quoted context omitted.

I was traveling with a friend and we could benefit from changing flights. So my friend went to the counter to just ask about the possibility. He had my boarding pass but not my passport. He returned 20 minutes later with both boarding passes changed. The counter stuff just took his "word" for "he is my friend". Edit: An hour later driving and thinking about it, I think it is the right move from the airline. The risk…

At least here in Brazil, airlines are expected to authenticate you at boarding time and not a second earlier. This is the sanest option too, since they will have to authenticate you at boarding time anyway, and anything earlier will at most cause a mild economical loss for the company.

I always wonder about that. Often, in the line at the boarding gate several agents will walk around, compare your boarding pass with your passport (and your face), and then draw a squiggle on your boarding pass (sometimes with a coloured felt-tip pen, sometimes with a biro/ballpoint pen).

It seems to me that it would be trivial to squiggle on your boarding pass yourself, and then claim that you've been checked already. I wonder how much security theatre is happening there, too.

Re: Post a boarding pass on Facebook, get your account stolen

#258
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

You can't do that with United Airlines. The answers have to be picked from a drop-down of answers.

Re: Post a boarding pass on Facebook, get your account stolen

#259

Earlier quoted context omitted.

Yes, I try to make the fake answer sound legitimate though City you were born? Just pick any (random/unrelated) city instead of 2DXSDGREDV@#! It's easier if you have to go through a person (which is usually forced to go through a script) also easier on the phone

I believe the general recommendation I saw was to type something in lines of "never accept this answer - it's probably someone trying to impersonate me | 2DXSDGREDV@#!" (although it's probably hard to do so if the maximum acceptable length is too short)

I had this thought as well, but figured I'd make sure no one else already posted it. Kudos :). I was thinking something like this:

> Do NOT give ANY hints; only accept an EXACT answer; I will NEVER say I "forgot" this answer. 2DXSDGREDV@#!

Maybe add an "I test you occasionally." :D

If there's a length limit, trim and remove parts of that as you see fit. For example:

> NO hints! EXACT answer! NO exceptions! 2DXSDGREDV@#!

I'm going to do this at a few places, then call to test them :D.

Re: Post a boarding pass on Facebook, get your account stolen

#260
post #32

Earlier quoted context omitted.

Isn't embedding QR codes the reason they were created in the first place? It's an optical data format designed to be easy for computers to read. You're basically evaluating the cryptographic merits of CSV.

> You're basically evaluating the cryptographic merits of CSV. I am not. I am weighing features vs unintended harm. Yes, the airlines shouldn't be including this data in the barcodes. It is improper to expose end users to this liability. And simply telling them not to expose them isn't a solution. But if FB can detect harmful barcodes in an image, by all means they should remove the photo. This is no different than G…

Is there any data in the barcode that's not also printed (in plain text) on the boarding pass?
Post reply on HN