Live data from Hacker News

Congressman's phone password is 111111

gfycat.com

71–80 of 206 posts

Re: Congressman's phone password is 111111

#71

I always thought that Android's 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.

Is there a reason why the numbers aren't scrambled? This way you at least wouldn't be able to tell the password unless you saw the actual numbers.

Imagine how inconvenient that would be i.e. how much "phone engagement" would take a hit.

Re: Congressman's phone password is 111111

#72
post #62
post #15

Earlier quoted context omitted.

Nothing to do with intelligence either. Most people don't grasp the consequences of bad OPSEC, though they can fairly well understand why they should lock their door when away from home. Those people lack education on the topic.

It was a funny conversation with a senior developer when I noticed he had his business card and his key card to work on the same extensible thingy that you clip on to your pants. I remarked there's a reason why the key cards are unmarked, right? It isn't just individuals who can't into OPSEC though. Soon after this conversation, the company created a policy saying you have to pay $10 to get a new key card if you lose…

At a previous place, we had one single card for everything: enterprise restaurant, parking entrance, building entrance, Windows session, S/MIME signature & decryption... You were more or less unable to work without that card, so it was immediatly obvious if a card was missing.

I also agree with the conclusion (the risk of unreported lost cards outweighs the cost of a new key card).

Re: Congressman's phone password is 111111

#73
post #11

111111 is perfectly acceptable for a phone password. His password was just broadcast to the entire world; at least using 111111 means that he doesn't have any illusions about how secure it is. Phone passwords are for protecting things from your family.

>Phone passwords are for protecting things from your family.

I think what you actually mean is anyone who has physical access to your phone. If you lose your phone or it is taken by authorities, then you are at risk of having strangers access your data.

Re: Congressman's phone password is 111111

#74

Isn’t the real problem here that this was caught on video? Otherwise it’s just as secure as any other code.

No, it is not. These sorts of "I'm annoyed that I'm being forced to put in a password so I'll put the easiest one to type" passwords are in even the most basic password dictionaries, and are therefore susceptible to dictionary attack.

Sure, but if your angle of attack is "someone swiped my phone off my desk and wants to unlock it within the next 30 minutes before I wipe it remotely" then 111111 is as good as literally any other 6-digit pin code, unless the attacker just tries 111111. In which case 999999 is probably a better choice.

Re: Congressman's phone password is 111111

#75
post #10

I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way. I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they…

The boindfolds seem like extra work, I would just get a SUV and totally black out the rear, or well, put in some seats in the rear of a delivery van.

But I guess the boindfolds also had a psychological effect of "we mean business".

Re: Congressman's phone password is 111111

#76

Earlier quoted context omitted.

Is there a reason why the numbers aren't scrambled? This way you at least wouldn't be able to tell the password unless you saw the actual numbers.

I can't imagine a more annoying feature. My bank already does this where I cannot use the keyboard to type in digits, I have to use their own on-screen keyboard that's scrambled between every digit(!!!) and I can't imagine anything like that anywhere near my phone. Either pin-based protection is good enough for you, or if you need more security then switch to full a-Z password.

Bank's security relies on reports of the past decade/century, and also, that kind of setup can't be okay for the blind users... how the hell are they supposed to interact with this monstruosity?...

Re: Congressman's phone password is 111111

#77

The problem isn't the password or the camera that captured it. The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.

I'm really surprised he doesn't just use FaceID in this case.

Re: Congressman's phone password is 111111

#78
And yesterday over a dozen members of Congress barged into one of the Congressional versions of this site without authorization and while recording video, audio, and taking photos on their personal smartphones.

Here is a Twitter thread about why that is such a problem:

https://twitter.com/MiekeEoyang/status/1187032800572125191

Re: Congressman's phone password is 111111

#79

I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked. So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a ho…

When I was a kid my house was "broken into" but because the door was unlocked the police couldn't qualify it as breaking and entering. It was merely trespassing and my neighbor who did it got off. I was 12, these details may be a bit fuzzy. I chased the guy off so nothing was taken, he just walked in, saw me running to the door and ran back out. Supposedly he was just drunk and wandered into the wrong house anyway.

I'm curious what affect not locking your phone might have on police reports if your identity/etc is ever stolen and you need to provide police reports. Possibly nothing, but I can imagine some credit cards legal team working hard on that aspect of things in the event you're trying to convince AMEX to return $40k of transactions you supposedly didn't make yourself and need reversed because your phone was swiped while logged into some CC app and they copied your card number.

Re: Congressman's phone password is 111111

#80
post #55

Earlier quoted context omitted.

Sorry, I don't understand what you're trying to say. Why can't you guess the pattern by looking at the smudges?

A valid pattern on Android is to swipe the middle 3 dots backwards and forwards 3 times like left-middle-right-middle-left-middle-right. The smudge on the screen just shows it uses the middle three dots some number of times.

Not on Android 9 (tested on my Nokia 7 Plus). Once you pass on a dot, you can't get back to it. You also can't "jump over" dots (top left - top right is actually top left - top - top right).
Post reply on HN