Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

451–460 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#451
post #279
post #219

FedEx may have the worst and least secure digital platform for a major company. Some examples I’ve noticed: 1. I moved into a 10-unit apartment building and wanted to set up FedEx Delivery Manager. I just put in my new address, no verification whatsoever, and I was immediately given access to the previous tenant’s delivery instructions which included the buildings private garage code. Any thief could have done the sa…

Re password reset workflow issues: I had an account at a bank where password reset always failed. I had to go through a VERY convoluted process with customer website support to get it fixed. It turned out that the problem was that my registered email address was just two characters (my initials) to the left of the "@", e.g., ab@mydomain.com. They allowed me to enter and use it throughout the system without any error…

This comment just unlocked a new fear of mine.

I specifically got a custom domain and email address for any non-personal/"professional" comms, which is essentially just me@.com.

At least with non-ASCII characters in passwords, while I think it is stupid to not handle those properly, I can at least see some sort of an excuse there, no matter how weak it is. All it takes to mess this up is not thinking about handling those scenarios, so I can definitely see "this issue was created due to us not thinking about this possibility or not willing to deal with handling it."

But what's even the reason to not allow sub-3-character local portions of emails? How does one even mess those up, aside from intentionally setting some triggers for less than 3 characters in local portions of email addresses?

Re: Thanks FedEx, this is why we keep getting phished

#452

Earlier quoted context omitted.

That sounds like internal verification uses GPS. So in most cases it's going to be the customer's word against the astonishingly lazy driver's evidence.

I called them and questioned them about this - they didn't even come down my street, and yet claimed that they "attempted delivery". The customer service person was honest enough to say there was no code for the driver to say "too busy, can't meet my unrealistic targets".

> too busy, can't meet my unrealistic targets

At least that could explain why the driver showed up to the address without dropping off the package. If finding the package takes a non-trivial amount of time, it would add up over the course of the day.

It's otherwise just wild to me that the driver did 99% of the delivery and just noped out of the last 1%.

Re: Thanks FedEx, this is why we keep getting phished

#453

Earlier quoted context omitted.

People are still using Windows 7 -- it's the third most popular Windows version after 10 and 11 -- and it only supports Unicode 5.1. Emoji weren't officially supported until Unicode 6.0, though there are a subset of current emoji (less than a quarter) that work on Windows 7 in practice. Meanwhile the current standard is 15.1. There's no security or convenience necessity whatsoever for supporting emoji in passwords, b…

Windows 7 market share is barely at 3% on the internet per statcounter.com. Third place doesn't mean "popular", especially not right now. There's quite a bit of convenience, and some concomitant security, to using emoji in passwords. Emoji are high entropy code points that are easily visually distinguishable across most language boundaries. A "short" password of just emoji is going to have way higher entropy and be w…

3% of the internet is still an incredibly large amount of people.

Re: Thanks FedEx, this is why we keep getting phished

#454
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

PSA: If you are of a certain age, the last four digits might be roughly all of the useful entropy in your SSN. Be careful with them. Before 2011, the first three digits indicated the office that issued the number and the middle two (the "group number") were used in a publicly-known sequence. The Social Security Administration helpfully published periodic lists of the highest group number reached by each office. This…

Tangentially related - wouldn't that mean that if you are an immigrant, then you are at least theoretically somewhat safe from that enumeration type of an attack?

Because if I got my SSN in my late teens, then my date of birth shouldn't mean much at all to anyone trying to use that method you describe, right?

Re: Thanks FedEx, this is why we keep getting phished

#455
post #332

Earlier quoted context omitted.

Be careful about those chargebacks. I bought two new pixel phones directly from Google and only one arrived. Google support was of course awful and Fedex did absolutely nothing outside of asking me what color the phone was. lol I ended up reversing charges for the missing phone and Google immediately wrecked me - I was using Fi at the time so they killed my cell service and killed my ability to use Google Pay for any…

Retaliation for charge back probably elevates this from a civil matter to a criminal one; you should totally contact your local DA. They might think it's fun.

I wouldn't be surprised if it's just covered by the EULA. There's almost certainly a clause in there about Google being able to terminate service for any reason.

Re: Thanks FedEx, this is why we keep getting phished

#456
post #245

A while ago my wife applied for a home equity loan. At some point I got a call from someone claiming to be from the bank she had applied through (I forget which one), calling to make sure I approved the loan since the home is in both our names. He asked for my name, which I gave him, and then the last four digits of my social security number, which I also gave him. He then proceeded to ask for my full social security…

A bank called me to ask me security questions. I said that I would call back using the number on the bank's website. They said (and the bank confirmed when I did call the number) that there is no way to be transferred to the security question people when I call the bank - the only way is for them to call me. I explained that that was poor security practice. They said that I should just look at the caller ID to see th…

It’s a real mystery why, as soon as I heard about a bank founded by people who sounded like they had heard about the internet (Monzo, in the UK), I switched away from my venerable bank (NatWest) that, at the time still had security practices unsuited for the 18th century.

Appropriately enough, the last thing they did was to insist —demand, really— that, in 2018, I fax them my demand. It just so happens that this could have been relatively safe because, after asking everyone I knew for a week (including some venerable hackers), the only way that I found to send a fax was to ask the local branch of the same bank.

Asking them to authorize the transfer wasn’t possible (by showing them all relevant documentation). Asking them to let me send a fax, using their machine, to a sister branch to tell them to authorize a transfer without anyone verifying my ID, was fine.

Re: Thanks FedEx, this is why we keep getting phished

#458
post #279

Earlier quoted context omitted.

Re password reset workflow issues: I had an account at a bank where password reset always failed. I had to go through a VERY convoluted process with customer website support to get it fixed. It turned out that the problem was that my registered email address was just two characters (my initials) to the left of the "@", e.g., ab@mydomain.com. They allowed me to enter and use it throughout the system without any error…

This comment just unlocked a new fear of mine. I specifically got a custom domain and email address for any non-personal/"professional" comms, which is essentially just me@ .com. At least with non-ASCII characters in passwords, while I think it is stupid to not handle those properly, I can at least see some sort of an excuse there, no matter how weak it is. All it takes to mess this up is not thinking about handling…

> But what's even the reason to not allow sub-3-character local portions of emails? How does one even mess those up, aside from intentionally setting some triggers for less than 3 characters in local portions of email addresses?

Wild guess: someone copy-pasted an incorrect email address validation regex, and different parts of the system are using different criteria for email address validation.

Re: Thanks FedEx, this is why we keep getting phished

#459
post #360
post #337

Earlier quoted context omitted.

Terms of service from my bank say you're not allowed to give your PIN or secrets like one-time passwords (called "TAN" here) to third parties, not even the bank employees themselves. But when I contacted them about a phishing practice, it was A-OK because it was a "legitimate" website that phished your credentials to view the last 180 days of transaction histories, compute a credit score, and then withdraw the money.…

I've implemented the bank account checking flow for a German client in a purely B2B setting, and this is essentially based on the PSD2 directive, which requires all/some/most (not entirely sure) banks to provide exactly this functionality (google keywords "PSD2" and "XS2A"). The bank's T&C should reflect this ... somewhere. The main protection to you not getting scammed out of money this way is in the kind of TAN use…

AirBnB has adopted Plaid for credit card verification recently, which wants bank login credentials. Nope, never going to happen.

Re: Thanks FedEx, this is why we keep getting phished

#460
post #332

Earlier quoted context omitted.

Be careful about those chargebacks. I bought two new pixel phones directly from Google and only one arrived. Google support was of course awful and Fedex did absolutely nothing outside of asking me what color the phone was. lol I ended up reversing charges for the missing phone and Google immediately wrecked me - I was using Fi at the time so they killed my cell service and killed my ability to use Google Pay for any…

Retaliation for charge back probably elevates this from a civil matter to a criminal one; you should totally contact your local DA. They might think it's fun.

[dead]
Post reply on HN