Live data from Hacker News

Thanks FedEx, this is why we keep getting phished

troyhunt.com

541–550 of 576 posts

Re: Thanks FedEx, this is why we keep getting phished

#541

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.

Are you saying that "old one + number" is less secure than "old one"? That doesn't sound right.

Re: Thanks FedEx, this is why we keep getting phished

#542

Earlier quoted context omitted.

The worst part is it actually leads users to boasting about how they `beat the system', essentially telling their coworkers what their pattern is, making the password easier to guess.

I have long felt that organizations that require password rotation for employees should, when the users are changing their passwords, record and post the old password to an internal site (without any identification of the user) for educational (and mockery) purposes.

That will help attackers. People often make passwords similar to their old passwords. A machine learning model could be trained on this list.

Re: Thanks FedEx, this is why we keep getting phished

#543
post #146

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

Even if this rule technically seems benign, together with the forced change it encourages users to game the system leading to predictable patterns, eg adding a rotating letter or digit combo at the end of a same password.

Is that worse than the password without the rotating letter/digit?

Re: Thanks FedEx, this is why we keep getting phished

#544

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

In combination with forced changes, it leads to… Password1 Password2 Password3 Etc

Is that worse than

Password1

Password1

Password1

Etc?

Re: Thanks FedEx, this is why we keep getting phished

#545
post #194

Earlier quoted context omitted.

Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.

I mean it's great for 99% of your passwords and pretty much forces people into using randomized generated passwords.. but I still have to remember at least ONE password by heart. Whether it's 32 characters or 16 or what not, I still need SOME way to get into my password manager to even get to my passwords. So what, I'm going to make my password tacokissies69 and.. what, add a 0 every 6 months so I pass the 20 passwor…

I'm not really sure how this problem is related to banning using identical passwords as past passwords.

Re: Thanks FedEx, this is why we keep getting phished

#546

Earlier quoted context omitted.

You're reminding me of the time I realized that Schwab (a massive American bank/broker) truncated all passwords to 8 characters.

PayPal used to do the same thing, but even worse they weren't consistent about it. The page to create your password truncated it, but the login page did not. I found out the hard way when I couldn't log in because of that stupid behavior. Thankfully they fixed it at some point, but it's absolutely mind blowing to me that anyone thought it was acceptable in the first place.

This drove me absolutely crazy as well and I was equally shocked that anyone thought it was a good idea. Ended up going through several rounds of password resets before figuring it out. Further reinforced the perception that PayPal is a crap company and continue to avoid using them as much as possible.

Re: Thanks FedEx, this is why we keep getting phished

#547
post #444

Earlier quoted context omitted.

> just keep the parcel at the depot for a week until they have a driver who can actually make the trip. Depot workers can get up to the weirdest stuff. One time I was returning unused product (oil well perforating guns, a UN 1.4D explosive device) via Yellow Freight. I handed over the cases and signed all the appropriate paperwork to handover custody at the depot and went on about my day. The supplier called me ~10 d…

Lesson for US customers: If you really want your shipment to be delivered, add a bullet or a pinch of gunpowder to the shipment.

Someone once suggested that if you are travelling by air and absolutely must have your checked bag arrived with you - put a starter's pistol in there (and fill out the appropriate paperwork).

The chances of that baggage being lost or misdirected is basically zero.

Re: Thanks FedEx, this is why we keep getting phished

#548

Earlier quoted context omitted.

Putting aside the fact that the conclusion of this text is not at all what GP said... You do realize that this is not a law, not even a court decision, but that it is a prosecutor's opinion / suggestion to the court?? Yes, if two people are going to answer with the exact same link and nothing else, I'm going to answer both with the exact same comment.

It is a court decision. Citing the actual law and context for it.

Uh... Are we reading the same document?

> Opinion of Advocate General Mengozzi delivered on 6 March 2012.

> [...]

> In the light of the foregoing considerations, I suggest that the Court answer the question referred to it by the Oberlandesgericht as follows:

It is not the court's decision.

Re: Thanks FedEx, this is why we keep getting phished

#549

Earlier quoted context omitted.

You've done everything except talk to the one human being involved who appears at your residence every single day. If I was your letter carrier and knew you felt this way I'd honestly be hurt that you didn't bother to ask me about any of it. > the organization could use some serious cuts Miss the part about them being the backbone of package delivery in this country? Or the part where there's nobody to replace them?…

> the USPS is financially self-sustaining. Sarcasm I hope? https://thehill.com/opinion/congress-blog/4138391-the-usps-n...

Preventing DeJoy levels of sabotage lies outside the USPS remit.

Re: Thanks FedEx, this is why we keep getting phished

#550

Earlier quoted context omitted.

This is good but how to make it work for phone, email and txt messages ?

The way I see it, it works for all the above. Passkeys are available on all devices, and whatever contact method the attackers use will harvest a signed response with an invalid RPID (a credential that won't work). Is that the point you were making?

Yeah I’m thinking of how to integrate authn into messaging and phone apps. One idea is to add the phone to the web certificate so a remote check can be made during the call
Post reply on HN