Post a boarding pass on Facebook, get your account stolen
271–280 of 313 posts
Re: Post a boarding pass on Facebook, get your account stolen
#272Earlier quoted context omitted.
The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…
That might have been the theory of security questions early on. But by now I'm sure I've filled out security questions dozens of times. Whatever the intent, from my perspective as a user, they're in the "speed bump" category of security. For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying v…
This is a great idea. Not only can the police verify that a given photo ID matches the person in front of them, they can also verify that the ID is valid and unaltered by verifying that the details on the ID match the details in the DMV's database, eliminating fake IDs from being an issue. This wouldn't be 100% perfect -- maybe a really determined ID thief could get the DMV to issue them an ID in someone else's name -- but it would dramatically increase the risk and makes ID theft much harder to scale.
A federal effort to standardize an identity verification service across federal and local offices nationwide would be helpful. The service should be available to any entity (not only banks or financial entities) who wishes to verify the identity of a counterparty. The process and fee should be standardized nationwide, with the fee being break-even and paid by the entity requesting the verification.
Post offices are a good candidate to offer such a service, but would need some work to set up (unlike police agencies, I presume post offices don't have access to DMV databases).
Re: Post a boarding pass on Facebook, get your account stolen
#273Earlier quoted context omitted.
Bitcoin brain wallets based on obscure Africa poems have been successfully cracked. Don't trust your choice of obscure books to be sufficient.
I need to look into that some. If I walk into a library, pick a floor, aisle, shelf, book, and page at random (just walk, don't think about it), and use a phrase that is a minimum of 12 words long -- is that more random than what I presume happened here, where someone knew that their target liked that style of poetry and was able to concentrate their search on that genre? ( a "crib" in Bletchley Park terms) The comme…
Re: Post a boarding pass on Facebook, get your account stolen
#274Earlier quoted context omitted.
January 1st 1970 is sometimes known as "The Internet's birthday" for this reason..
It's also the "UNIX Birthday".
Re: Post a boarding pass on Facebook, get your account stolen
#275And this is also why I almost never give my real birth date when registering on websites (except on financial websites or websites where I'm legally obligated to) and I never ever give real answers to the security question.. My typical answer for a security question is something like "39arsrc uyrsrsaulsr8832r" and that's saved in a password manager Security questions weakens the security of an account, they are easil…
When I was in high school, SWIM was stealing everybody's MSN's accounts. The technique got out, it was through these "security questions", then SWIM got his MSN stolen. Then people would recreate MSN accounts and get it stolen again. It became a funny war until some dude started asking for money to other people's contacts (via allopass, these things where you could just call a number to get charged and obtain some to…
Re: Post a boarding pass on Facebook, get your account stolen
#276Earlier quoted context omitted.
You can't do that with United Airlines. The answers have to be picked from a drop-down of answers.
> I didn't believe you when I read this, but you are right. => https://krebsonsecurity.com/wp-content/uploads/2016/08/unite... and.. > Yes, you read that right: The answers are pre-selected as well as the questions. For example, to the question “During what month did you first meet your spouse or significant other,” users may select only from one of…you guessed it — 12 answers (January through December). > The list o…
Re: Post a boarding pass on Facebook, get your account stolen
#277Not the first time airlines have had poor security with boarding passes: https://medium.com/@da/need-a-last-minute-flight-45af88ec8df... https://www.wired.com/2016/08/fake-boarding-pass-app-gets-ha... https://puckinflight.wordpress.com/2012/10/19/security-flaws... http://www.washingtonpost.com/national/experts-warn-about-se... And what the OP article is basically copying: https://www.theverge.com/2017/1/10/14226034/i…
The real problem is that once again someone treated what should simply be an identifier to look up data as something more. Why not store all this information on the server that an authorized person can see when they scan a uuid on the boarding pass? Would they allow boarding of the network was down?
Re: Post a boarding pass on Facebook, get your account stolen
#278Earlier quoted context omitted.
Not that they can really know, but most I've seen is that they disable pasting anything into the website, effectively making banking super slow for us with password managers and long passwords. Fortunately, my bank doesn't disable pasting (Banc Sabadell in Spain). Instead the password is restricted to maximum 6 numbers for login. Yay banks!
6 characters? Let me guess, were there restrictions on character space and case? One place I had an account has a password input that restricts all of those, so it's like an 8-10 character string of all capital letters. I don't understand it at all.
Re: Post a boarding pass on Facebook, get your account stolen
#279Earlier quoted context omitted.
Sure. So is there nothing to my intuition above? If you were to have users choose between (a) and (b) above, is (b) generally safer than (a)? Much safer? Only marginally so? When using a password manager that presents 10 passwords, should I always choose the first one to remove my choice from the equation? Are those few bits I've removed that important, given that the entire set is random? I'm not trying to catch you…
A user-chosen password have exactly 0 bits of guaranteed randomness. A randomly generated password has X bits of randomness, and a list of Y passwords of X bits each, where the user is allowed to choose exactly one of the passwords, has exactly X−(log2(Y)) bits. So, to answer your questions: Your intuition is correct – since user-chosen passwords do not contain any guaranteed randomness, generated passwords are bette…
Re: Post a boarding pass on Facebook, get your account stolen
#280It's not just posting photos that can cause this kind of trouble. I get a lot of email intended for other Doug Webbs sent to my gmail account, with variations on the presence/location of periods, or CC'd with another gmail account that's the same but with numbers on the end. For a while I was getting boarding passes from a major airline for a Doug that was frequently flying up and down the US west coast. Those emails…
- Thailand holiday itineraries and airline tickets
- A PayPal money request for $1800
- Congratulations from someone's godfather that I am now able to play the opening riff of AC/DC's "Hells Bells"
- South African real estate quotes
- A bar mitzvah invitation
- A reply to a Thanksgiving invitation sent by someone else
- Inquiries about racehorse sponsorship
- South African Taser training course booking confirmation
- British Heart Foundation cycling team invitations from a BBC reporter
- Complaints from an Ebay purchaser that I'd sent them a Nutribullet with a broken blade
- Confirmation that my NJCAA hardship application had been granted
- Pictures of 5th graders riding trail bikes in Eagle Lake, Maine
- Solicitations from the Greater Palm Harbor Area Chamber of Commerce to run a stall at the 13th Annual Palm Harbor Parrot Head Party
- Sports tipping results
- House painting estimates
I'd be living a much more exciting life if all of these had been intended for me.