Live data from Hacker News

I could send any text message from Indian government IDs

kmskrishna.me

41–46 of 46 posts

Re: I could send any text message from Indian government IDs

#43
post #15

Shared secret authentication is pretty much always a bad idea. I'm continually shocked people still use it.

So what is the better option according to you?

Some kind of PKI, probably with an organization wide CA.

Re: I could send any text message from Indian government IDs

#44

Earlier quoted context omitted.

Brave? Or dumb? Using someone else’s credentials is against the law in most jurisdictions.

Intent tends to matter. I once reported an exposed AWS access key (someone posted it to StackOverflow) to AWS support and they weren't quite sure what to do with it; gave me instructions on how to disable it in the Console, but it wasn't mine. I gave up after a couple rounds and just committed it to Github; their credential monitoring bot disabled it within seconds.

I’m not sure what that anecdote says about the legality of using these keys to authenticate as someone you’re not.

Re: I could send any text message from Indian government IDs

#45
post #39

Earlier quoted context omitted.

My sibling comment, that's how I've understood the situation to be for well over 20 years. Don't downvote because of some current political situation you think he's commenting on.

Regardless of the current political situation, it's not worth commenting on. That's why you're getting downvoted.

Comments all brought back. Some people disagree with you, there.

That's okay.

Re: I could send any text message from Indian government IDs

#46

Earlier quoted context omitted.

Intent tends to matter. I once reported an exposed AWS access key (someone posted it to StackOverflow) to AWS support and they weren't quite sure what to do with it; gave me instructions on how to disable it in the Console, but it wasn't mine. I gave up after a couple rounds and just committed it to Github; their credential monitoring bot disabled it within seconds.

I’m not sure what that anecdote says about the legality of using these keys to authenticate as someone you’re not.

I misused someone's credentials with good intent. It's an example of why intent matters, and the CFAA (and lots of other laws) includes wording like "knowingly and with intent to x" in quite a few spots.
Post reply on HN