Live data from Hacker News

Post a boarding pass on Facebook, get your account stolen

michalspacek.com

301–310 of 313 posts

Re: Post a boarding pass on Facebook, get your account stolen

#301
post #272

Earlier quoted context omitted.

That might have been the theory of security questions early on. But by now I'm sure I've filled out security questions dozens of times. Whatever the intent, from my perspective as a user, they're in the "speed bump" category of security. For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying v…

> For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying via internet form is pretty easy. Walking into a building with 100 cops bearing fake ID is a whole different level. This is a great idea. Not only can the police verify that a given photo ID matches the person in front of them, they can…

> This wouldn't be 100% perfect -- maybe a really determined ID thief could get the DMV to issue them an ID in someone else's name

This is much more common than you might think. I believe in Illinois there was some sort of ongoing problem with people at the DMV selling licenses to truckers who didn't actually pass their tests[0]. I'm sure any criminal with a wad of cash could get them to make a fake ID.

[0]: http://www.chicagotribune.com/news/chi-991009license-story.h...

Re: Post a boarding pass on Facebook, get your account stolen

#302
post #207

Earlier quoted context omitted.

It's also built into 1Password. And before that, I just used what I think was literally a one- or two-line Perl script that just grabbed four words from /var/dict. Why yes, my mother's maiden name was indeed pathetic xylophone tootsie wasp, how did you know?

The entire point of security questions is that their answers are supposed to be things that are permanently stored in your memory, that you are physically incapable of forgetting because they are so ingrained. If you store these in a password manager, it is possible to lose them - and that is unacceptable. These are supposed to be the very last line of defense for security, including if lose your password manager. As…

> These are supposed to be the very last line of defense for security, including if lose your password manager.

Security questions aren't for security, they're against it. They're a tradeoff between security and usability, in the direction of usability. Assuming you answer security questions truthfully, they weaken the security of your account. It's like having multi-factor authentication, but instead of requiring all the factors, they just require any one of them. That's not necessarily a bad thing, as long as it doesn't weaken the security so much that it's easy to break.

> Of course, it's terrible to use personal information that can be known to 3rd parties. It's also bad to reuse the same answers across multiple companies, as a compromise at one means you're at risk everywhere.

And here's the problem. Many/most sites that use security questions have a dropdown list of acceptable questions and don't let you enter your own. Often the only thing you can do to avoid making your account easily compromised is to make up answers to some of the questions.

The downside, is, of course, the usual downside with security tradeoffs that favor the security side of the equation: you may be completely unable to access your account again if you screw this up. And that's also not necessarily a bad thing, if you believe compromise to be a really bad outcome. I think it might be ok to do this for, say, a bank or brokerage account. If you manage to fully and truly lock yourself out online, likely you'll still be able to prove who you are and gain access through some means like visiting a physical branch and showing them your ID. A hassle, to be sure, but if it means that much to you, it might be worth it.

In the end, social engineering is still the biggest problem: other posters in this thread have claimed that they've gotten past the security questions by saying things like "oh, I just mashed the keyboard, that's why my answer is gibberish", or something like that. So there's no way to win, unless perhaps you invent plausible (but incorrect) answers to the questions. "Mother's maiden name? Well, it's actually Jones but I'm going to put in Smith." I imagine a talented social engineer might still be able to get past that, but at some point you just have to acknowledge you've done the best you can.

Re: Post a boarding pass on Facebook, get your account stolen

#303
Do a thoroughly stupid thing, reap the consequences. Post publicly a bunch of private info, like your complete contact details, get your account (or more of your identity) stolen.

There is nothing surprising about that, nothing hard to understand.

What is hard is actually thinking about what you are doing. Maybe, well, showing off your sophisticated and aesthetically perfect password is not such a good idea due to other considerations.

Re: Post a boarding pass on Facebook, get your account stolen

#304

It would also help if tickets had a "No photography" icon on them and a note about them having private information.

I think somebody should develop a standardized and open auto redaction flagging scheme for anything printed, where cameras and any software meant to share photos can offer the user to redact every sensitive field in a secure manner. Something like a Qr code saying "this stuff in that position relative to this code is sensitive", giving the user a prompt saying "this was redacted; undo?"

Maybe something similar to the EURion constellation[0]?

[0] https://en.wikipedia.org/wiki/EURion_constellation

Re: Post a boarding pass on Facebook, get your account stolen

#305
post #242

Earlier quoted context omitted.

You just need a larger number of random words to reach the same entropy as random passwords. It's not like your random password is made up from secret alphabets!

Sentences aren't random.

You seem to be misunderstanding how diceware works. You randomly generate numbers by throwing dice. Every five rolls indexes exactly one "diceware" word. So even if an attacker knew we were using diceware, each word contains

    log2(6^5) = log2(7776) ≈ 12.9 bits
of entropy. If you want 128 bits of etropy in your security question field, then just randomly generate 10 diceware words. This is comparable to choosing 20 random printable ascii characters or so.

Since we pick the words by literally throwing dice, English grammar has nothing to do with it.

Re: Post a boarding pass on Facebook, get your account stolen

#306
how about just don't post stuff like boarding pass online >.> don't need to share every detail on the PUBLIC INTERWEBZ. dm someone if u want to tell them. saves hastle of getting your shit stolen by some 12 year old. in holland we say 'voorkomen is beter dan genezen' -> to prevent is better than to cure. We all know these kind of weakeneses exist everywhere, yet we post our boarding pass on a public page on the internet... bit silly. you can say 'shit should be secure' but thats being said since the dawn of the interwebz and it never has been... so dont bank on it ever being secure is better than to assume it is and point fingers once you're a victim.

Re: Post a boarding pass on Facebook, get your account stolen

#307

Earlier quoted context omitted.

This is a reference to the XKCD comic, Password Strength [1]. [1] https://xkcd.com/936/

And for those who think the reference is so well known it doesn't need citing: https://xkcd.com/1053/

Quite Frankly - bad math. You judge people based on how old they are..

Re: Post a boarding pass on Facebook, get your account stolen

#308
post #254
post #141

Earlier quoted context omitted.

Or use a memorable phrase from literature. > This was not the last encounter between Bobby Shaftoe and Goto Dengo

Median novel has some 65k words. Take all (consecutive) quotes of 2 to 24 words, and you have some 1.5m phrases. Take the top 666k books (apparently there've been about 130m titles been published in total, about 5m in the Amazon Kindle store), and you're at about 1e12 phrases, or 40 bits of entropy, or worse than a password with 7 random letters/digits/symbols. You could probably improve on it considerably by selecti…

I am pretty confident that some phrases would repeat.

Re: Post a boarding pass on Facebook, get your account stolen

#309
post #242

Earlier quoted context omitted.

Sentences aren't random.

You seem to be misunderstanding how diceware works. You randomly generate numbers by throwing dice. Every five rolls indexes exactly one "diceware" word. So even if an attacker knew we were using diceware, each word contains log2(6^5) = log2(7776) ≈ 12.9 bits of entropy. If you want 128 bits of etropy in your security question field, then just randomly generate 10 diceware words. This is comparable to choosing 20 ran…

I was responding to someone who was recommending using sentences from books as passwords. Hence the comment about grammar.

Re: Post a boarding pass on Facebook, get your account stolen

#310
post #272

Earlier quoted context omitted.

> For things like house, car, and life savings, I'm perfectly glad to go somewhere with physical ID. Heck, I'd love to see police stations offering this as a municipal service. Lying via internet form is pretty easy. Walking into a building with 100 cops bearing fake ID is a whole different level. This is a great idea. Not only can the police verify that a given photo ID matches the person in front of them, they can…

> This wouldn't be 100% perfect -- maybe a really determined ID thief could get the DMV to issue them an ID in someone else's name This is much more common than you might think. I believe in Illinois there was some sort of ongoing problem with people at the DMV selling licenses to truckers who didn't actually pass their tests[0]. I'm sure any criminal with a wad of cash could get them to make a fake ID. [0]: http://w…

This is true, but I think there's an important distinction.

Driving a truck is generally legal. Stealing somebody's life savings generally isn't.

This matters because once an underqualified truck driver is on the road, they're going to be hard to distinguish from a normal truck driver. You have to issue a lot of licenses before the pattern of fake licenses becomes obvious enough to trigger an investigation.

Granting fake licenses for serious theft, though, is another matter. Every single one of those will trigger a police investigation. It's much higher risk, meaning it'd be very hard to sustain an ongoing business in fake licenses for theft.

Post reply on HN