Live data from Hacker News

Stop Hacklore – An Open Letter

hacklore.org

71–80 of 115 posts

Re: Stop Hacklore – An Open Letter

#71

So, since this seems to be relevant im a CISO myself. And i would definitely not agree with everything in this letter. Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices. To take on point as example - the "never scan public QR codes". Apart from the fact that there have been enaugh exploits in the past…

>Personally, i think the worst part about it is handling a low probability as something that's not gonne happen. Thats, especially in IT-Sec, one of the worst practices.

If you are an online service provider, sure. Low probability means it's going to happen, especially as you scale with users.

For a small business IT team? You can't keep a clean sheet, the strategy is to reduce the probabilities of an incident and reducing its damage, but it will never be zero, if only because you have non-technical users that need to do actual work.

p(incident) is just yet another variable you need to do tradeoff engineering on, and obsessing over reducing it to 0 will probably compromise other tradeoffs like ease of use of the system.

It's a special case of ironic when in an attempt to get a specific variable to 0 (which is impossible with most variables anyways) you end up compromising that specific variable. So if you force users to use lots of passwords and password managers and MFA, and limit their capabilities, they end up circumventing your security systems and advice, so they introduce an issue (but of course it will be the users fault, and not the CISO's fault, their job is secure).

Re: Stop Hacklore – An Open Letter

#72

This has the energy of "Remove all DEI initiatives because we have solved workplace discrimination." > This kind of advice is well-intentioned but misleading. It consumes the limited time people have to protect themselves and diverts attention from actions that truly reduce the likelihood and impact of real compromises. I dislike any methodology that claims its intent is to talk down to people for whatever declared r…

> People are capable, and should be helped to make decisions based on all available information.

To relay a quote, with the source not being very important: "I'm not going to waste a dime on cybersecurity when my officers need bullets and armor." People can be intelligent and capable and have minimal (if you're lucky) bandwidth or tolerance for cybersecurity advice. It's not the crisis they see every day. The advice given to unwilling listeners has to be focused and prioritized.

And... Password leaks and therefore rotations aren't an issue if people are using a strong main password for their manager. Then a leak doesn't transfer to another account and the manager will loudly tell them when a password is found in breach data -- which lines up with NIST's modern advice of avoiding password complexity and rotation, since they've found it to lead to minimal (at best) gained security.

Re: Stop Hacklore – An Open Letter

#73
post #21
post #6

> Never scan QR codes: There is no evidence of widespread crime originating from QR-code scanning itself. > The true risk is social engineering scams... Exactly. My grandma is very susceptible to phishing and social engineering, I don't want her scanning random QR codes that would lead to almost identical service to the one she would think she is on and end up with identity theft or the likes. > Regularly change pass…

> Database leaks happen all the time The point is to use unique passwords. If there is a leak, hopefully it is detected and then it is appropriate to change the password.

Sure, if you use unique passwords, then changing passwords isn't as useful. Yet we shouldn't judge a security policy based on the existence or not of another policies.

What you are judging then is a whole set of policies, which is a bit too controlling, you will most often not have absolute control over the users policy set, all you can do is suggest policies which may or may not be adopted, you can't rely on their strict adoption.

A similar case is on the empiric efficacy of birth control. The effectiveness of abstinence based methods is lower than condoms in practice. Whereas theoretically abstinence based birth control would be better, who cares what the rates are in theory? The actual success rates are what matters.

Re: Stop Hacklore – An Open Letter

#74
post #66

Don't worry about cookies or bother using a VPN, because... you are being tracked anyway? What's the point of including such a defeatist stance? > the real world across industry, academia, and government. Gotcha, so no one here gives a shit about privacy. They only care about avoiding the inconveniences of fraud and leaked secrets. Use a password manager and a feature-complete adblocker (ublock origin on Firefox). Se…

BTW, I really would like to have a way to partially clear cookies – i.e., I don't want to be signed out of gmail, and maybe not out of the Mechanic's Bank of Alaska or Amazon or Netflix, but most other things could go. I don't think this is easy in Chrome, Safari or other mainstream browsers, is it? Yesyes, I do know that Big Ad can mostly stitch together some proxy profile of me anyway, but it would be more blurry.

Firefox has a great feature for this: multi-account containers. The UI is trash, but it's usable.

Re: Stop Hacklore – An Open Letter

#75

Slight tangent: My wife's place of work has recently instituted a minimum 16-character password rule with the standard complexity requirements. They also encourage the use of password management software, as well as enforcing password changes every 6 months. Where I see a flaw in this is the initial login. If you're not already on your computer to access the password manager, how do you retrieve the essentially non-m…

I've not met anyone who doesn't just increment a digit at the end every 6 months.

And any password length requirement beyond 8 always ends up being just a logical extension of 8 character password (like putting 1234 at the end), if 16 characters is required one would just type their standard password in twice.

If a any of the old passwords (potentially from unrelated applications) get leaked, it's almost trivial to guess current password.

Re: Stop Hacklore – An Open Letter

#76
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

Updating software is good advice. Do you realize how many CVEs are reported on a daily basis? Once you've got a password manager you're largely protected against phishing, so the biggest target becomes your computer, and the most likely way to compromise that would be through outdated software with public vulnerabilities. What do you expect your browser security levels to the max to do? Browsers are designed to be se…

CVEs are better viewed as "a uniform numbering system that ensures we are talking about the same bug" today. But updating software is good anyway.

> Browsers are designed to be secure from default settings.

Not quite. They are usually designed to be both fast and safe, but neither goal is considered "done" yet in modern ones. If you want max security, you'll likely have to disable all performance boosts like JS JIT.

Re: Stop Hacklore – An Open Letter

#77
post #24

I have two more to add to the list: > Secret questions No, my mother's maiden name is not a secret. And some questions like "who was your best friend in elementary school?" might have different answers depending on when you ask me. Plus, unless my best friend's name was Jose Pawel Mustafa Mungabi de la Svenson-Kurosawaskiwitz (we used to call him Joe) it's pretty easy to guess with a dictionary attack. The only way t…

There seems to be an easy solution: use a password manager and save the answer to the question as an additional password.

(This is actually a FR to any password manager's product team: it's time to treat things like 2FA recovery code and secret question answers as first class citizen in your product).

Re: Stop Hacklore – An Open Letter

#78
post #77
post #24

I have two more to add to the list: > Secret questions No, my mother's maiden name is not a secret. And some questions like "who was your best friend in elementary school?" might have different answers depending on when you ask me. Plus, unless my best friend's name was Jose Pawel Mustafa Mungabi de la Svenson-Kurosawaskiwitz (we used to call him Joe) it's pretty easy to guess with a dictionary attack. The only way t…

There seems to be an easy solution: use a password manager and save the answer to the question as an additional password. (This is actually a FR to any password manager's product team: it's time to treat things like 2FA recovery code and secret question answers as first class citizen in your product).

KeepassXC already supports 2FA.

Re: Stop Hacklore – An Open Letter

#79
post #8

Note that most of the signers are from companies which collect substantial consumer information for revenue purposes. Hence the emphasis on "updating". And the absence of "turn up browser security levels to max" or "get a good ad blocker". Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right.

> Also, any password manager that's "cloud based" is potentially a security hole. Yeah, they say the server is secure. Right. The entire point of end-to-end encryption is that you don't need to trust the server. If your password manager has access to your secrets (i.e. you don't control the secret key/password itself), then you have bigger problems than a potentially untrustworthy host.

We use 1Passwodr at work, at my suggestion from 10-12 years ago where it was an app on your device with an encrypted on device file you could chose to store on iCloud/Dropbox/GoogleDrive/wherever.

Then they changed to the web app and implemented teams, which is what we use today.

Work has decided the risk of 1Password going rogue is acceptable - but that's in the full knowledge that since they are serving the Javascript that's doing the client side encryption/decryption, there's no guarantee they can't serve (or be coerced into serving) malicious JavaScript that decrypts and exfiltrates all credentials and secrets any user has access to.

Pragmatically, I'm (mostly) OK with accepting that. If we have a threat model that realistically includes the sort of state level actor who could coerce a company like 1Password to launch an exploit against us - then we've lost already. Like James Mikkens said "YOU'RE STILL GONNA BE MOSSAD'D UPON!!!"

One of my hobbies is recreational paranoia though. So I use something else (KeyPass) for my personal stuff now.

Re: Stop Hacklore – An Open Letter

#80
post #75

Slight tangent: My wife's place of work has recently instituted a minimum 16-character password rule with the standard complexity requirements. They also encourage the use of password management software, as well as enforcing password changes every 6 months. Where I see a flaw in this is the initial login. If you're not already on your computer to access the password manager, how do you retrieve the essentially non-m…

I've not met anyone who doesn't just increment a digit at the end every 6 months. And any password length requirement beyond 8 always ends up being just a logical extension of 8 character password (like putting 1234 at the end), if 16 characters is required one would just type their standard password in twice. If a any of the old passwords (potentially from unrelated applications) get leaked, it's almost trivial to g…

Yeah, that's kinda my point, increasing the complexity requirements counter-intuitively reduces, or at least doesn't change, the actual level of security provided.

It's a wetware limitation. Not that we don't have methods that could improve it, it's just that they're not yet implemented at this specific point of contact. Interestingly.

Post reply on HN