Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

61–70 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#61
post #29

Earlier quoted context omitted.

Without sharing examples, this is effectively a non-answer. Thanks for the comment.

In Sweden, BankID covers well over 90% of the population between ages 20 and 60 with a unique electronic ID. (Including 98% of those between 20 and 40.) It supports identifying yourself with a credit card and pin using a card reader given to you by your bank or alternatively (and more commonly) a pin combined with a smartphone/computer that you have identified as being yours.

BankID covers well over 90% of the population between ages 20 and 60

What do the other 206,868 people do?

If a similar system were implemented in the United States, that would leave 6,514,383 out. What do you do with six million people who can't be part of the standard ID scheme?

Re: Finding vulnerable Twitter accounts with expired domains

#62
post #14

Even though they show the starred email address and one of the suggestions is not to show the email, I really hope people don't do that. There is nothing more frustrating when you're recovering your password and the site says we have sent you an email with no hint where and even worse sometimes they say "if that email was in our records then you should get the link" and you're wondering did that work and #1 worst is…

I don’t think you having to either A) remember what email you used or B) creating a new account is a big ask when the alternative is leaking your account presence on a given system. Not everyone wants other people to be able to essentially query a given app for an email account.

The vast majority of people don't use the same e-mail address for their entire lives.

Re: Finding vulnerable Twitter accounts with expired domains

#63
post #57
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

We should be using biometric markers filtered through homomorphic encryption. This way we can verify/prove our identity without handing over those markers to multiple 3rd parties.

Biometrics are unrevokable. If yours are compromised through some other way then you can’t trust biometric authentication for the rest of your life.

Re: Finding vulnerable Twitter accounts with expired domains

#64

What would be a universal solution to this problem? The only thing I can really think of is platforms not allowing custom domains for connected email accounts, but that seems sub-optimal.

2FA that can't be bypassed with a password reset?

Re: Finding vulnerable Twitter accounts with expired domains

#65
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

> Without emails as the keys to the kingdom, what would you use?

PKI. Service providers shouldn't give you access to an account just because you can prove you control an email address (during a narrow and predictable time window, no less). The simplest thing would be to encrypt the relevant part of the payload (the one containing the password reset link), so resets are only possible if you can receive the email and have the means of reading it in its "true" form.

Failing that (suppose you've not just lost your password but also the ability to decrypt the contents of the message), there should be an alternative, but the threshold for proving your identity should increase. It would ameliorate a lot if it meant that people had to show up in person somewhere. E.g., I show up at either the business's local branch (if there is one) or the USPS (or...) with my photo ID. From there, an attestation is generated that you really are who you say you are, and only with that attestation will your account be unlocked.

Re: Finding vulnerable Twitter accounts with expired domains

#66
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

Gmail is only a single failure point if you let it be one though - set up 2fa on all your accounts, and this problem is solved.

Google bans/locks/deletes accounts for arbitrary reasons all the time, with absolutely zero recourse for the user.

Re: Finding vulnerable Twitter accounts with expired domains

#67
post #3

This was a common way to harvest 6-digit ICQ numbers back in the day. Hotmail, MSN etc. had expiring email addresses as well that you could register to reset the password to the ICQ number.

Yeah this has been a common attack since as early as I can remember. Company goes bust? Wait for their domain to expire then register/catch-all and start seeing what mail you get from websites to see where there’s accounts using that domain. Also plenty of more targeted methods too.

Re: Finding vulnerable Twitter accounts with expired domains

#68
post #14

Earlier quoted context omitted.

I don’t think you having to either A) remember what email you used or B) creating a new account is a big ask when the alternative is leaking your account presence on a given system. Not everyone wants other people to be able to essentially query a given app for an email account.

The vast majority of people don't use the same e-mail address for their entire lives.

Those users are already creating new email accounts, so creating a new e.g. FooApp account shouldn’t seem unreasonable to those users.

Re: Finding vulnerable Twitter accounts with expired domains

#69
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

I want a private key embedded in a chip, that never leaves that chip, so all encryption and decryption happens on that chip—similar to how chip-and-pin credit cards work now. I'm identified by the corresponding public key. Then I want to embed that chip in my hand. Then I can unlock my car, house, computer, or phone and sign into any online service the same way: you send me a challenge token, I sign it with my private key then send it back.

Re: Finding vulnerable Twitter accounts with expired domains

#70
post #63
post #57

Earlier quoted context omitted.

We should be using biometric markers filtered through homomorphic encryption. This way we can verify/prove our identity without handing over those markers to multiple 3rd parties.

Biometrics are unrevokable. If yours are compromised through some other way then you can’t trust biometric authentication for the rest of your life.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself.

The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can’t reasonably ensure that you’re taking a reading from a living human then you shouldn’t be using biometrics.

Biometrics is not transmitting a picture of a fingerprint, it’s presenting your hand.

Having your email secured by a password locked by a device you trust doing biometric auth is perfectly fine. Having a website somehow store your print isn’t.

Post reply on HN