Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

31–40 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#33

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

How is that going to help? Are people going to be expected to use a unique username per site? And password recovery is still going to let someone take over.

It wont solve the problem, it also would not have prevented THIS issue. However -- many, many people use one email address for more or less everything in their lives. It's best if someone has no pieces of the puzzle, rather then have it half solved for them already. Especially when it's something like your first and last name as part of the address.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#34

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

With every platform, there is compromise between convenience and security; when your platform has to reach many, many non-tech-y people, convenience is preferred.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#35

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

On the contrary, for a great many sites (low impact) I'm happy that they finally figured out to use my email address as a username. As a usability feature, it's much nicer than having to guess at whether my standard usernames are taken.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#36
post #29

Earlier quoted context omitted.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

The most surprising thing I see out of this isn't the need for more robust authentication but for services that aren't so damn quick to do whatever you want. Website: "Hey Bill, glad to see you today, what do you want to do" Bill: "Delete _everything_ I've ever done on every system I have" Website: "Of course! Let's get this started... beep boop bip and done!" What about this: 1 - Kill request sent 2 - 48 hours is se…

Once I moved and realized I forgot to cancel my phone and DSL. On the road, I used my cell to call the phone company to cancel. They did it for me immediately.

I was relieved it was so easy, but unnerved at how easy it was.

Maybe they had the cell associated with my land line, but I doubt it, since I got the line before I ever had a cell.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#38
post #35

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

On the contrary, for a great many sites (low impact) I'm happy that they finally figured out to use my email address as a username. As a usability feature, it's much nicer than having to guess at whether my standard usernames are taken.

There are many problems with this. Among them that I have some iTunes purchases associated with an email account that hasn't existed in /years/. There's no way to rename an Apple account. This same problem exists on most sites that use email as username - if your email address of choice ever changes, you're SOL on having a single identity anymore.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#39
post #12

Earlier quoted context omitted.

If you're trying to remote-wipe your computer so that a thief doesn't access your sensitive data, wouldn't you want the data to be lost permanently?

Could be. But that's a very different problem. Old-school computer security breaks things down into the CIA categories: Confidentiality is for things you want secret. Integrity is for things you want to not be altered. Accessibility is for things you want to be able to reach. Honestly, very little of data requires confidentiality. Yet that's what encryption is usually used for. I would, by an order of magnitude, rath…

Interesting - hadn't heard that CIA thing before.

I run a business. A good deal of what is on my laptop I would put in the confidentiality category. I guess apps and settings would come under integrity.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#40
post #13

Earlier quoted context omitted.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

run your own server.

...until the hacker calls up your registrar and convinces them to reset your domain management password.
Post reply on HN