Live data from Hacker News

When two-factor authentication is not enough

blog.fastmail.fm

51–57 of 57 posts

Re: When two-factor authentication is not enough

#51

Earlier quoted context omitted.

> And this is not a problem that is specific to Gandi. Even with other online services, it's often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol' snail mail. I wonder if this is actually a counter-intuitive advantage of AWS, which, as far as I can tell, offers absolutely zero, zip, nada human support.

Actually they do for MFA problems, even if you don't have paid support on your account. A few years ago I wiped my phone without first disabling MFA on my account (I use Google Authenticator). After business hours on a holiday, I submitted the support form [0] and got a call from a human five minutes later. He asked me several questions and deactivated MFA so I could log in. [0] https://portal.aws.amazon.com/gp/aws/h…

They called you. That makes a huge difference. Problem if you called them from public phone.

Re: When two-factor authentication is not enough

#52

Earlier quoted context omitted.

I think Google actually stand to lose less than a smaller corporation. The registry will not assign Google to another company in any way that passes any eyeballs without seriously questioning it; if it did get re-assigned then they wouldn't have a problem recovering it. It's not likely to be gone for more than a few seconds before it's noticed and customers who were phished, or whatever, wouldn't be that likely to le…

I would agree that any attempt to reassign google.com ought to raise someone's eyebrows. But I would have said the same about mit.edu and they got reassigned about a year ago. Obviously not for long, but the damage someone well-prepared could do by owning google.com for just 30 minutes is scary.

There's no way anyone could own it for more than a couple of minutes before Google had contacted the managers of the root name servers and ICANN to revert. Like the sibling comment intimates handling the traffic would be nigh impossible - easier to control and perform a localised attack on a nameserver to "own" google.com for a limited subset of users.

Re: When two-factor authentication is not enough

#53
post #18

Although Gandi.net is a fantastic company, their security practices are nothing to write home about. A few years ago, one of my clients lost access to her Gandi.net account. Unfortunately, she had the "disable password resets via email" option set in her account. That should have given her quite a headache, right? Nope. I, an independent contractor who didn't even own the account, was able to convince Gandi support t…

Google is one of the few companies I've dealt with that generally does not easily fall victim to social engineering of this nature.

Re: When two-factor authentication is not enough

#54
If you are opposed to this modification, thank you for letting us know only by replying to this email.

If you can read this message, then you can recover the password of your account, and thus modify the email address of the handle. In that case, we won't take care of your request.

I get that they are not native English speakers, but if I got an email like that I'd be VERY likely to conclude that it was phishing and ignore it. It just reads like so many of those broken-English "Kind Sir, your email quota has been exceeded, please to click here to revalidate your password account" mails I get every other day.

Hire an English speaking writer to draft your email notices.

Re: When two-factor authentication is not enough

#55
That email message from Gandi is _so_ confusing, at first I thought the story was going to be about how it was a phishing attempt!

> If you can read this message, then you can recover the password of your account, and thus modify the email address of the handle. In that case, we won't take care of your request.

Wait... what?

Re: When two-factor authentication is not enough

#56
The article links to a Schneier article which suggests using random keyboard mashing as an answer to "Security" questions. This is all well and good until you need to use the Australian Government Centrelink application, in which not one, but FIVE "Security" questions are requested.

And then, without any warning, you're obliged to provide your password AND the answer to a random one of those questions when you log in.

Guess how long I was on hold for...

Re: When two-factor authentication is not enough

#57

The passport will be obviously forged. A hacker won't have even done a good job it doesn't matter because people don't check. This process was described in a candid interview with a hacker that tried to take over the interviewers website - in it he points out that social engineering is the easiest way around security. http://shoptalkshow.com/episodes/special-one-one-hacker/

Especially since this request was done by snail mail, so the passport was probably a black-and-white photocopy. All the attacker needs to alter is the name, which seems pretty trivial.
Post reply on HN