Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

271–280 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#272

Earlier quoted context omitted.

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

That might have been the theory of security questions early on. But by now I'm sure I've filled out security questions dozens of times. Whatever the intent, from my perspective as a user, they're in the "speed bump" category of security. For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying v…

> For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying via internet form is pretty easy. Walking into a building with 100 cops bearing fake ID is a whole different level.

This is a great idea. Not only can the police verify that a given photo ID matches the person in front of them, they can also verify that the ID is valid and unaltered by verifying that the details on the ID match the details in the DMV's database, eliminating fake IDs from being an issue. This wouldn't be 100% perfect -- maybe a really determined ID thief could get the DMV to issue them an ID in someone else's name -- but it would dramatically increase the risk and makes ID theft much harder to scale.

A federal effort to standardize an identity verification service across federal and local offices nationwide would be helpful. The service should be available to any entity (not only banks or financial entities) who wishes to verify the identity of a counterparty. The process and fee should be standardized nationwide, with the fee being break-even and paid by the entity requesting the verification.

Post offices are a good candidate to offer such a service, but would need some work to set up (unlike police agencies, I presume post offices don't have access to DMV databases).

Re: Post a boarding pass on Facebook, get your account stolen

#273
post #266

Earlier quoted context omitted.

Bitcoin brain wallets based on obscure Africa poems have been successfully cracked. Don't trust your choice of obscure books to be sufficient.

I need to look into that some. If I walk into a library, pick a floor, aisle, shelf, book, and page at random (just walk, don't think about it), and use a phrase that is a minimum of 12 words long -- is that more random than what I presume happened here, where someone knew that their target liked that style of poetry and was able to concentrate their search on that genre? ( a "crib" in Bletchley Park terms) The comme…

What's happening is that people collect endless phrases and alter them with a ton of standard manipulation schemes, compute the corresponding private and public keys & addresses for all the variations, create a lookup table for the addresses and private keys, and as soon as they see a known keypair in use then they use the corresponding private key to swipe the funds.

Re: Post a boarding pass on Facebook, get your account stolen

#274
post #124

Earlier quoted context omitted.

January 1st 1970 is sometimes known as "The Internet's birthday" for this reason..

It's also the "UNIX Birthday".

Right, leave it blank when enrolling → Empty value coerced to number becomes 0 → Recorded in Unix timestamp format where 0 is Jan 1 1970 → Wow, everyone was born then?

Re: Post a boarding pass on Facebook, get your account stolen

#275
post #55
post #11

And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…

When I was in high school, SWIM was stealing everybody's MSN's accounts. The technique got out, it was through these "security questions", then SWIM got his MSN stolen. Then people would recreate MSN accounts and get it stolen again. It became a funny war until some dude started asking for money to other people's contacts (via allopass, these things where you could just call a number to get charged and obtain some to…

i had to look it up: SWIM = Someone Who Isn’t Me

Re: Post a boarding pass on Facebook, get your account stolen

#276

Earlier quoted context omitted.

You can't do that with United Airlines. The answers have to be picked from a drop-down of answers.

> I didn't believe you when I read this, but you are right. => https://krebsonsecurity.com/wp-content/uploads/2016/08/unite... and.. > Yes, you read that right: The answers are pre-selected as well as the questions. For example, to the question “During what month did you first meet your spouse or significant other,” users may select only from one of…you guessed it — 12 answers (January through December). > The list o…

12 possible answers… little better than a 1-digit PIN!

Re: Post a boarding pass on Facebook, get your account stolen

#277
post #2

Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…

The real problem is that once again someone treated what should simply be an identifier to look up data as something more. Why not store all this information on the server that an authorized person can see when they scan a uuid on the boarding pass? Would they allow boarding of the network was down?

Can you imagine how slow boarding might be if the information needed retrieved from a distant mainframe by the scanner before it would emit its _beep_ of consent? (I agree with you, though)

Re: Post a boarding pass on Facebook, get your account stolen

#278
post #146

Earlier quoted context omitted.

Not that they can really know, but most I've seen is that they disable pasting anything into the website, effectively making banking super slow for us with password managers and long passwords. Fortunately, my bank doesn't disable pasting (Banc Sabadell in Spain). Instead the password is restricted to maximum 6 numbers for login. Yay banks!

6 characters? Let me guess, were there restrictions on character space and case? One place I had an account has a password input that restricts all of those, so it's like an 8-10 character string of all capital letters. I don't understand it at all.

You read wrong, not 6 characters but 6 numbers. So no spaces or casing.

Re: Post a boarding pass on Facebook, get your account stolen

#279
post #250
post #197

Earlier quoted context omitted.

Sure. So is there nothing to my intuition above? If you were to have users choose between (a) and (b) above, is (b) generally safer than (a)? Much safer? Only marginally so? When using a password manager that presents 10 passwords, should I always choose the first one to remove my choice from the equation? Are those few bits I've removed that important, given that the entire set is random? I'm not trying to catch you…

A user-chosen password have exactly 0 bits of guaranteed randomness. A randomly generated password has X bits of randomness, and a list of Y passwords of X bits each, where the user is allowed to choose exactly one of the passwords, has exactly X−(log2(Y)) bits. So, to answer your questions: Your intuition is correct – since user-chosen passwords do not contain any guaranteed randomness, generated passwords are bette…

FWIW, I see several examples with two numbers and up to four uppercase letters. There's a clear bias toward lowercase letters though.

Re: Post a boarding pass on Facebook, get your account stolen

#280

It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…

My Gmail account was one of the first created. Here's a quick list of emails I've received intended for other people:

- Thailand holiday itineraries and airline tickets

- A PayPal money request for $1800

- Congratulations from someone's godfather that I am now able to play the opening riff of AC/DC's "Hells Bells"

- South African real estate quotes

- A bar mitzvah invitation

- A reply to a Thanksgiving invitation sent by someone else

- Inquiries about racehorse sponsorship

- South African Taser training course booking confirmation

- British Heart Foundation cycling team invitations from a BBC reporter

- Complaints from an Ebay purchaser that I'd sent them a Nutribullet with a broken blade

- Confirmation that my NJCAA hardship application had been granted

- Pictures of 5th graders riding trail bikes in Eagle Lake, Maine

- Solicitations from the Greater Palm Harbor Area Chamber of Commerce to run a stall at the 13th Annual Palm Harbor Parrot Head Party

- Sports tipping results

- House painting estimates

I'd be living a much more exciting life if all of these had been intended for me.

Post reply on HN