Live data from Hacker News

Major Toronto Utility Company Stores Customers' Passwords in Plain Text

old.reddit.com

41–50 of 89 posts

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#41
post #37

Earlier quoted context omitted.

What city were you born in: “Millwaukee”. The agent would be able to tell it was Milwaukee, but if he or she typed “Milwaukee” it’d go “bzzzzt” just because the user typoed the input initially at set-up.

It's still awful security. city of birth is public info

It’s just an example to illustrate a point. Coulda been “Starbux lovers” instead of “starstruck lovers”.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#42

Earlier quoted context omitted.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

How can you be sure that a targeted attack can't exfiltrate all available fields? For the record, I don't have a great answer to this either -- genuinely curious.

You can't. I see that as a far lesser/more manageable risk than traditional security questions are though.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#43

Earlier quoted context omitted.

I don't see why the security question answer has to be stored in the clear. If you have to give it over the phone, the agent can type it into a form field that hashes it and compares, just like a password on the site.

Because security question answer have high variability for the average user. They're asked say, what street they grew up on. Is it "S. Main St." "South Main", "south main", "south main street", etc... Security questions in general are terrible so don't take this as if it's in defense of them. My favorite are the presumptive ones that assume something like "Where did you meet your spouse?" Someone should just go over…

My bank's list of security questions are almost all about your children or your spouse.

Other than two about your birth location and mother's maiden name, both easily found answers for someone

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#44
post #43

Earlier quoted context omitted.

Because security question answer have high variability for the average user. They're asked say, what street they grew up on. Is it "S. Main St." "South Main", "south main", "south main street", etc... Security questions in general are terrible so don't take this as if it's in defense of them. My favorite are the presumptive ones that assume something like "Where did you meet your spouse?" Someone should just go over…

My bank's list of security questions are almost all about your children or your spouse. Other than two about your birth location and mother's maiden name, both easily found answers for someone

There's viral social media posts that do security answer farming with prompts like

"Your superhero name is the name of your pet + favorite teachers name"

You'd click on the comments and there's tens of thousands of people volunteering answers. Some are of part of the hustle to till the honeypot, but I'd see people I know comment on them with real information. It's wild

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#45
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

"What's your mother's maiden name?"

"42_red_banana_&"

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#46
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

Ditto. Have you ever had to use one? It's always a laugh.

CSR: What's your mother's maiden name? Oh wait, looks like an issue on our side.

Me: No issue. My mother's maiden name is Q5D6Erty#76cjWE1H. She's Dutch.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#47
post #18

This is a misunderstanding. The CS agent has access to a plaintext (security question) password that can be used under special circumstances. It must be readable to function.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

If you're storing it next to the password, then you've killed the point of the recovery questions anyway. May as well not store them at all.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#48
post #43

Earlier quoted context omitted.

Because security question answer have high variability for the average user. They're asked say, what street they grew up on. Is it "S. Main St." "South Main", "south main", "south main street", etc... Security questions in general are terrible so don't take this as if it's in defense of them. My favorite are the presumptive ones that assume something like "Where did you meet your spouse?" Someone should just go over…

My bank's list of security questions are almost all about your children or your spouse. Other than two about your birth location and mother's maiden name, both easily found answers for someone

For some of us, finding our mother's maiden name is as simple as looking at our name, either because it is a hyphenated name or because there was a time when the government refused to acknowledge the existence of the father in certain cases.

It is very hard to come up with universally good security questions.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#49
post #46

Earlier quoted context omitted.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

Ditto. Have you ever had to use one? It's always a laugh. CSR: What's your mother's maiden name? Oh wait, looks like an issue on our side. Me: No issue. My mother's maiden name is Q5D6Erty#76cjWE1H. She's Dutch.

I did do this once, but it didn't really inspire confidence in the security of the whole thing.

Me: "ok, but it's some random text: Q 5 --"

CSR: "--yeah, ok, that's fine"

Since then I just make up a random, fake but real-sounding answer so the humans don't get confused.

Re: Major Toronto Utility Company Stores Customers' Passwords in Plain Text

#50
post #47

Earlier quoted context omitted.

My solution to security/recovery questions is to generate or make up ransom answers, and store the question/answer pair in the notes field of the entry in my password manager. This kills the “knowing things about you” vector of phishing and impersonation and make it as secure as any unique and random password.

If you're storing it next to the password, then you've killed the point of the recovery questions anyway. May as well not store them at all.

If that's an option it's usually what I do but often they're mandatory.
Post reply on HN