Earlier quoted context omitted.
You are also trusting the Oauth provider to never login as you for their own inscrutable purposes.
Absolutely. In the case of Facebook, it's easy to imagine them logging into websites as you to slurp up your contact list on that site. Don't worry, you agreed to it somewhere in the thousand pages of small print! Or as the case of twitter demonstrates, you're also trusting all future owners of the Oauth provider, whoever they may be. If an erratic billionaire with a penchant for breaking the rules whenever it suits…
“Invalid Username or Password”: a useless security measure (2014)
281–289 of 289 posts
Re: “Invalid Username or Password”: a useless security measure (2014)
#282Earlier quoted context omitted.
That works fine till you have the access to your password manager. If you ever find yourself without it... imagine your Apple device got broken/stolen. You would be fine wihtout an ability to talk on some forum, but what about critical banking, e-gov sites?
My passwords are synced between all of my devices - iPad, iPhone, and Mac. Even if I lost all of my devices, I could walk into a store, buy a new device and log in and all of my passwords with be in sync.
Lol.
You lost your cards with the phones/wallet. Or perhaps you didn't even had one, because Apple Pay. Well, at least you have one at home, so now you just must make it back... without money. Oh, somehow you have given enough cash to buy a new iDevice, great. Do you still remember the password, after years of FaceID?
You just never been in the situation where you lost your "IT life", along with "bank life" and "any government accepted ID life". Try it for a day or two, report back.
Re: “Invalid Username or Password”: a useless security measure (2014)
#283> Check submitted passwords against a dictionary of common passwords (123456, monkey, etc) and ban that traffic extra hard. > Give guidance to users about creating strong passwords Yeah, if I just want to talk about a propane with some folks I would eagerly wait to be lectured about IT security, scolded at my passwords of choice, go out of my way to appease site administrator's password policy...
The internet you want no longer exists. Stealing your account talking about propane sounds like a great way for me to inject spam/propaganda right in the middle of a group of trusted individuals. And this is exactly what we see countless times. Accounts with bad passwords get compromised, spam, then banned. You're using a shared resource, you need to use it responsibly.
> Accounts with bad passwords get compromised, spam, then banned
Just like any other account with a proper good password (10 char, 3/4? Certain e-gov site recently forced me for a 12-char, 4/4 without any 3 chars of the sitename in a row) on a proper good one-time/one-use email address... which was compromised by a malware running on the user's machine. Forcing a stupid password policies only increases the friction for a new (and sometimes existing) users, while not providing a meaningful increase in 'non-compromising'.
Re: “Invalid Username or Password”: a useless security measure (2014)
#284Earlier quoted context omitted.
Those sites probably prompt the attacker with a "We have sent you an email with an activation link" and the owner receives the "you tried to sign up, but you seem to have an address already" message. In this way they don't leak anything to the attacker. By the way, I've been stuck for years with an ecommerce site that thinks I already registered with them using my email. They're telling me that I must activate the ac…
I'm confused, you've been trying to buy an item from that website for years and it never occurred to you to just use a different email address? This isn't really believable.
Re: “Invalid Username or Password”: a useless security measure (2014)
#285Earlier quoted context omitted.
My passwords are synced between all of my devices - iPad, iPhone, and Mac. Even if I lost all of my devices, I could walk into a store, buy a new device and log in and all of my passwords with be in sync.
> buy a new device Lol. You lost your cards with the phones/wallet. Or perhaps you didn't even had one, because Apple Pay. Well, at least you have one at home, so now you just must make it back... without money. Oh, somehow you have given enough cash to buy a new iDevice, great. Do you still remember the password , after years of FaceID? You just never been in the situation where you lost your "IT life", along with "…
I also had to go to the bank first to get money without my ID to get my ID. There are ways to verify that too.
Re: “Invalid Username or Password”: a useless security measure (2014)
#286Earlier quoted context omitted.
> buy a new device Lol. You lost your cards with the phones/wallet. Or perhaps you didn't even had one, because Apple Pay. Well, at least you have one at home, so now you just must make it back... without money. Oh, somehow you have given enough cash to buy a new iDevice, great. Do you still remember the password , after years of FaceID? You just never been in the situation where you lost your "IT life", along with "…
I have lost my ID once. There are ways to get your government ID when it’s lost. They have your picture and your information. There are procedures to verify it. I also had to go to the bank first to get money without my ID to get my ID. There are ways to verify that too.
I'm glad what that worked for you, but here you would be told to get back with a proper ID. Nobody at the bank would risk their job even for $150.
> There are ways to get your government ID when it’s lost
Yes, sure, just like hundreds of years before? The question here is what without an ID you can't get the same phone number => you can't request password recovery for bazillions of services which treats SMS as 2FA for the password recovery. Banking apps are one of those.
I would repeat again, but try to 'lose' your wallet and the phone, preferably in some place 500+km from your home. Your opinion on some account/password policies would change.
Re: “Invalid Username or Password”: a useless security measure (2014)
#287Earlier quoted context omitted.
I have lost my ID once. There are ways to get your government ID when it’s lost. They have your picture and your information. There are procedures to verify it. I also had to go to the bank first to get money without my ID to get my ID. There are ways to verify that too.
> There are ways to verify that too I'm glad what that worked for you, but here you would be told to get back with a proper ID. Nobody at the bank would risk their job even for $150. > There are ways to get your government ID when it’s lost Yes, sure, just like hundreds of years before? The question here is what without an ID you can't get the same phone number => you can't request password recovery for bazillions of…
I’ve never shown my ID to get a phone for T-mobile or walked into the store. I even switched my service with the same number from AT&T to Verizon back in 2011 without going into the store. I entered some verification information and Verizon sent me an iPhone 4S. I logged into my iPhone 4S with my Apple ID and everything downloaded from iCloud - data, apps, and the screen layout. My Verizon phone became active and my AT&T phone deactivated with the same number.
> you can't request password recovery for bazillions of services which treats SMS as 2FA for the password recovery. Banking apps are one of those.
I can log into any Apple device with my Apple ID and receive SMS messages - not just iMessages. Currently, if I get an SMS message, it goes to my phone, my cellular Apple Watch, my iPad and my Mac.
If I forget my iCloud password , my wife can help me recovery it (https://support.apple.com/en-us/HT212515).
My wife and I would have to lose six cellular equipped devices between us and both of our wallets not to have any access to anything.
> I would repeat again, but try to 'lose' your wallet and the phone, preferably in some place 500+km from your home. Your opinion on some account/password policies would change.
Well, seeing that my “home” right now is whatever city I happen to be in with my wife this week (doing the whole digital nomad thing across the US), I’ve thought a lot about that.
If I lost my wallet and needed cash, I call American Express and take advantage of my Global Assist privileges (https://www.americanexpress.com/content/dam/amex/us/credit-c...) that come with the Amex Platinum.
If I lost my phone. Hopefully I wasn’t mugged and I still have my Watch where I can make calls (at least in the US) from the same number and receive texts. My iPad also has a cellular connection that receives SMS messages from the same number. While it doesn’t have a dialer for regular calls, you can call a number from your contacts.
Re: “Invalid Username or Password”: a useless security measure (2014)
#288"99.9% of websites on the Internet will only let you create one account for each email address. So if you want to see if an email address has an account, try signing up for a new account with the same email address." Yes, but signing up is a more cumbersome process and usually has a CAPTCHA attached to it, unlike logging in.
> Yes, but signing up is a more cumbersome process and usually has a CAPTCHA attached to it, unlike logging in. My guess of what is most common is that the actual trying to create a user in the backend/database is protected by a captcha, but checking if the email/username already exists is a separate endpoint that the frontend hits while filling out the signup form, before trying to create the actual user. But it's j…
I'm sure this happens in some cases, but it's definitely not a good practice, would hopefully get flagged by any pentesting or security audit, and also, most people use some sort of framework for auth (devise for Rails, Spring Security for JVM, or similar) - and those usually don't work in that way.
Re: “Invalid Username or Password”: a useless security measure (2014)
#289Earlier quoted context omitted.
Even an async validation would be better. I have @gmail.com, and get several newspapers and some other subscriptions for free. In one case, a person named Mary in Australia sends their loved one a gift card every year, and the retailer doesn’t provide any information about Mary. In another case, a student missed out on their work study job and a opportunity for early class enrollment due to a bad email. It’s sad as a…
Validating any contact method that has the potential of sending PII, Health, or financial data should be mandatory by law. At least once a year I get an automated phone call from a regional hospital letting me know some minor's test results. Calling the hospital's CS department in order to notify them or somehow get my phone number removed from the account is impossible, because I'm not this person nor their legal gu…
I get all kinds of messages to someone called Amy from multiple sources, so I believe Amy really had my phone number earlier. No medical results yet, but healthcare appointment reminders for sure.