Live data from Hacker News

Finding vulnerable Twitter accounts with expired domains

zainamro.com

71–80 of 128 posts

Re: Finding vulnerable Twitter accounts with expired domains

#71
post #51
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

There are other aspects here. If you use a third party service for your email ID, the third party can ban you or like you mention - disappear and basically take your identity away. If you rely on national ID cards, you have another set of problems. If you rely on phone numbers, these can be sim-jacked. If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromise…

>If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromised.

It's my understanding that these methods (TouchID, FaceID) don't actually store your thumb prints or images of your face rather they store hashes of the output. Similar to how passwords should never be stored in plain text.

Re: Finding vulnerable Twitter accounts with expired domains

#72

Earlier quoted context omitted.

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

I want a private key embedded in a chip, that never leaves that chip, so all encryption and decryption happens on that chip—similar to how chip-and-pin credit cards work now. I'm identified by the corresponding public key. Then I want to embed that chip in my hand. Then I can unlock my car, house, computer, or phone and sign into any online service the same way: you send me a challenge token, I sign it with my privat…

The security and privacy implications of this are horrifying to me, as are they to enough of the population that I doubt this will get widespread adoption.

Re: Finding vulnerable Twitter accounts with expired domains

#73

Even though they show the starred email address and one of the suggestions is not to show the email, I really hope people don't do that. There is nothing more frustrating when you're recovering your password and the site says we have sent you an email with no hint where and even worse sometimes they say "if that email was in our records then you should get the link" and you're wondering did that work and #1 worst is…

Oh, much better is the "you tell us what email you told us" approach.

Re: Finding vulnerable Twitter accounts with expired domains

#74
post #70
post #63

Earlier quoted context omitted.

Biometrics are unrevokable. If yours are compromised through some other way then you can’t trust biometric authentication for the rest of your life.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can…

> Biometrics is not transmitting a picture of a fingerprint, it’s presenting your hand.

What would this "hand data" look like? A 3D model of a hand MRI or X-Ray?

Based on my understanding, in any form of biometric authentication, some amount of static data (i.e. the biometric database is not receiving a secure, updating feed of the state of your hand/body) is stored on the server and compared with the data transmitted for authentication. Biometrics change (fingerprints can be rubbed off from gardening, DNA mutates, etc.), so this static biometric data is something that is mostly environment-invariant.

If someone can compromise your "full hand scanner" or compromise the biometric database (which will inevitably happen), then you are compromised for life, since you cannot change your hand.

Re: Finding vulnerable Twitter accounts with expired domains

#75
post #51
post #12

At some point in time we decided that email addresses control the keys to the kingdom. If you lose access to your email, there goes your social media accounts, your bank accounts, your gaming accounts, and potentially many of your commercial accounts as well. And then we decided that custom domains are the most professional. Which does make sense, there can only be one 'robert@gmail.com'. But, this is coupled with th…

There are other aspects here. If you use a third party service for your email ID, the third party can ban you or like you mention - disappear and basically take your identity away. If you rely on national ID cards, you have another set of problems. If you rely on phone numbers, these can be sim-jacked. If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromise…

The problem is that every new source of identity added is another new attack vector. If there are 10 different ways for me to prove I am who I say I am, it only takes a security flaw in one for my account to be compromised.

Re: Finding vulnerable Twitter accounts with expired domains

#76

Earlier quoted context omitted.

You point out some problems, but how do we actually do these? Without emails as the keys to the kingdom, what would you use? Without a global identifier for a human person (like social security in the US), how would we declare that an identity is compromised? While I believe your ideals are well-intentioned, I think they're impractical in our current society. I would propose that an email is the key to the kingdom, t…

I want a private key embedded in a chip, that never leaves that chip, so all encryption and decryption happens on that chip—similar to how chip-and-pin credit cards work now. I'm identified by the corresponding public key. Then I want to embed that chip in my hand. Then I can unlock my car, house, computer, or phone and sign into any online service the same way: you send me a challenge token, I sign it with my privat…

And when I lose that chip, or it is damaged or stolen?

Re: Finding vulnerable Twitter accounts with expired domains

#77
post #71
post #51

Earlier quoted context omitted.

There are other aspects here. If you use a third party service for your email ID, the third party can ban you or like you mention - disappear and basically take your identity away. If you rely on national ID cards, you have another set of problems. If you rely on phone numbers, these can be sim-jacked. If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromise…

>If you rely on bio-authentication methods, you risk your privacy especially when the master database gets compromised. It's my understanding that these methods (TouchID, FaceID) don't actually store your thumb prints or images of your face rather they store hashes of the output. Similar to how passwords should never be stored in plain text.

Its more than a hash since it needs to be able to match similar inputs (face at different angle, partially obscured), its probably just a bunch of raw measurements but not actually a photo of your face.

The upside is its only stored on the device itself and not in a master database and also isn't used for any remote authentication so can't be exploited by hackers over the internet.

Re: Finding vulnerable Twitter accounts with expired domains

#78
post #70
post #63

Earlier quoted context omitted.

Biometrics are unrevokable. If yours are compromised through some other way then you can’t trust biometric authentication for the rest of your life.

But that doesn’t matter! I hate this argument because it misses the point of biometric authentication as “something you are.” There’s no such thing as compromise or revocation. It’s a piece of public information that can’t be stolen or used by anyone other than yourself. The world can have high def scans of my fingerprint for all it matters, they can’t produce a living human finger with the same print. And if you can…

It sounds like both your biometric information and your password is actually stored on your local machine, then.

What happens when you lose the local machine?

Re: Finding vulnerable Twitter accounts with expired domains

#79
post #14

Earlier quoted context omitted.

I don’t think you having to either A) remember what email you used or B) creating a new account is a big ask when the alternative is leaking your account presence on a given system. Not everyone wants other people to be able to essentially query a given app for an email account.

The vast majority of people don't use the same e-mail address for their entire lives.

I think the vast majority of people use two... a personal one and a work one. Someone could easily check both for a person.

Re: Finding vulnerable Twitter accounts with expired domains

#80
post #4

What would be a universal solution to this problem? The only thing I can really think of is platforms not allowing custom domains for connected email accounts, but that seems sub-optimal.

If you deliver email to a customer and you notice that it bounces, any account security flows requiring access to that email should be disabled. Additionally, you should never show the full email address or phone number that is being used for an auth challenge. Nonetheless, those defenses will eventually be compromised. Beyond that, it is not a company problem IMO. One of the most common uses for custom domains is cu…

I think you underestimate how often there are intermittent mail delivery failures, especially for custom domains.
Post reply on HN