Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

31–40 of 57 posts

Re: When two-factor authentication is not enough

#31

Earlier quoted context omitted.

I've heard this claim made repeatedly on this site, but I've not heard any details as to what specifically MarkMonitor does to protect domains above and beyond other registrars. Anyone care to chime in?

I realize it's an appeal to authority, but if there is one company that would have a lot to lose if its domain was ever exploited, it's google. http://reports.internic.net/cgi/whois?whois_nic=google.com&t...

I think Google actually stand to lose less than a smaller corporation. The registry will not assign Google to another company in any way that passes any eyeballs without seriously questioning it; if it did get re-assigned then they wouldn't have a problem recovering it. It's not likely to be gone for more than a few seconds before it's noticed and customers who were phished, or whatever, wouldn't be that likely to leave Google because of it.

That said I think appeal to authority is quite useful in this situation.

Re: When two-factor authentication is not enough

#32
The passport will be obviously forged. A hacker won't have even done a good job it doesn't matter because people don't check. This process was described in a candid interview with a hacker that tried to take over the interviewers website - in it he points out that social engineering is the easiest way around security. http://shoptalkshow.com/episodes/special-one-one-hacker/

Re: When two-factor authentication is not enough

#33
post #26

Can anyone recommend a registrar who takes domain security seriously? (think, £ six digit value domain names)

When you're at that level of risk you probably need to worry as much about the registry as the registrar. If a corrupt registrar can simply bypass your registrar and claim the domain for example.

Yes, agreed. The domains in question are .com TLD

Re: When two-factor authentication is not enough

#34
Online games separate your public handle from your login username (typically your email address). If someone wants to take over LazerBob, they have to first guess his username.

It's nowhere near sufficient by itself, but it cuts down on the noise dramatically.

Many email addresses should be considered sensitive, in that you want any attempt to talk to them to get close personal attention from several senior people. "hostmaster@fastmail.fm" should be changed to "hostmaster-9508gdgs42x@fastmail.fm" simply to reduce the amount of noise going to it. Don't publish it in your whois or on your blog; tell it only to your domain manager.

You can't count on it staying secret forever, of course.

Re: When two-factor authentication is not enough

#35

Earlier quoted context omitted.

I realize it's an appeal to authority, but if there is one company that would have a lot to lose if its domain was ever exploited, it's google. http://reports.internic.net/cgi/whois?whois_nic=google.com&t...

I think Google actually stand to lose less than a smaller corporation. The registry will not assign Google to another company in any way that passes any eyeballs without seriously questioning it; if it did get re-assigned then they wouldn't have a problem recovering it. It's not likely to be gone for more than a few seconds before it's noticed and customers who were phished, or whatever, wouldn't be that likely to le…

I would agree that any attempt to reassign google.com ought to raise someone's eyebrows.

But I would have said the same about mit.edu and they got reassigned about a year ago. Obviously not for long, but the damage someone well-prepared could do by owning google.com for just 30 minutes is scary.

Re: When two-factor authentication is not enough

#36
post #30

Earlier quoted context omitted.

A possible reason was called out in the article: "Gandi’s paper 'email reset' form makes a lot of sense in the world where most of their customers are individuals or small businesses with one or two domains, and using addresses that they may lose access to. With no other factors, if they lose access to the email address and forget their password, there needs to be a process to regain access." If a customer loses acce…

Why not send a reset code to the registered address or phone number? Or they could pay some money into the registered bank account with a special code that would only be visible on a bank statement (like Paypal).

People move physically and change their phone numbers, too.

You don't have a bad idea, you just need to consider all the effects.

Re: When two-factor authentication is not enough

#37

Earlier quoted context omitted.

> And this is not a problem that is specific to Gandi. Even with other online services, it's often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol' snail mail. I wonder if this is actually a counter-intuitive advantage of AWS, which, as far as I can tell, offers absolutely zero, zip, nada human support.

Actually they do for MFA problems, even if you don't have paid support on your account. A few years ago I wiped my phone without first disabling MFA on my account (I use Google Authenticator). After business hours on a holiday, I submitted the support form [0] and got a call from a human five minutes later. He asked me several questions and deactivated MFA so I could log in. [0] https://portal.aws.amazon.com/gp/aws/h…

Well, that's great, except, according to the article at the top of this thread, that's maybe not so great, depending on what kind of questions they asked you.

So, what kind of questions did they ask you?

Re: When two-factor authentication is not enough

#39
post #30

Earlier quoted context omitted.

Why not send a reset code to the registered address or phone number? Or they could pay some money into the registered bank account with a special code that would only be visible on a bank statement (like Paypal).

People move physically and change their phone numbers, too. You don't have a bad idea, you just need to consider all the effects.

It is not like you have a perfectly verified identity in the first place. There are no photos or biometrics that could uniquely identify the person in the absence of the things like address or phone. Most websites do not verify identity but the provenance of the user (is it the same person?). Establishing actual identity is just more difficult and mostly unnecessary.

Re: When two-factor authentication is not enough

#40
post #39

Earlier quoted context omitted.

People move physically and change their phone numbers, too. You don't have a bad idea, you just need to consider all the effects.

It is not like you have a perfectly verified identity in the first place. There are no photos or biometrics that could uniquely identify the person in the absence of the things like address or phone. Most websites do not verify identity but the provenance of the user (is it the same person?). Establishing actual identity is just more difficult and mostly unnecessary.

For my personal domain, yes, that's overkill.

For the places where it's really necessary, like fastmail, they should have physical photos of all the principals on hand.

It's expensive, but it's also an extremely precious resource they need to guard at all times.

Post reply on HN