Live data from Hacker News

Hackers account for 90% of login attempts at online retailers

qz.com

1–10 of 65 posts

Re: Hackers account for 90% of login attempts at online retailers

#3
post #2

This makes sense given how often they'd fail. When I log in it takes me one attempt. When someone is using stolen credentials they might have to make hundreds of attempts before actually logging in.

That, and most websites remember your computers forever so you rarely ever need to log back in.

Re: Hackers account for 90% of login attempts at online retailers

#4
post #2

This makes sense given how often they'd fail. When I log in it takes me one attempt. When someone is using stolen credentials they might have to make hundreds of attempts before actually logging in.

The ratio is waaaay higher for ssh login attempts.

Re: Hackers account for 90% of login attempts at online retailers

#6

Article doesn't talk about what they're doing to mitigate the problem. Well, except tell the reader to change their passwords. So are online retailers just hoping the problem goes away?

The only way I see this problem going away is when regular retailers start supporting software and hardware two factor authenticators.

I use Google Authenticator on any website that supports it and it does not impact the customer experience at all and it really improves security.

Re: Hackers account for 90% of login attempts at online retailers

#8
post #7

This has to do with affiliate schemes. Payouts for them are quite solid. Clickfraud people, I think, count on the the fact that for huge e-retailers, it takes months to take action, and they can cashout affiliate payouts faster then they react.

It's far more than affiliate schemes. Credential stuffing attacks result in account takeovers for many different types of companies and the value that can be extracted is different for each business.

Re: Hackers account for 90% of login attempts at online retailers

#9
post #6

Article doesn't talk about what they're doing to mitigate the problem. Well, except tell the reader to change their passwords. So are online retailers just hoping the problem goes away?

The only way I see this problem going away is when regular retailers start supporting software and hardware two factor authenticators. I use Google Authenticator on any website that supports it and it does not impact the customer experience at all and it really improves security.

Agreed, but keep account recovery in mind.

Account recovery is a major pain point for any site that supports TOTP 2FA. If you're not using a TOTP application that supports cloud backup (like Authy), when you lose or replace your mobile device the existing TOTP tokens are useless as they can't be recovered. This results in some type of account recovery process to reintroduce the 2FA tokens. Often these recovery processes introduce additional security issues that are equivalent to not supporting 2FA at all, or they might require costly human intervention.

Don't get me started on SMS 2FA.

Re: Hackers account for 90% of login attempts at online retailers

#10

Article doesn't talk about what they're doing to mitigate the problem. Well, except tell the reader to change their passwords. So are online retailers just hoping the problem goes away?

They have to balance user attention and user friction. Online retailers want your purchase to be as smooth as possible. There's some studies on how someone won't spend much time on a website if it loads slow. The same can apply to purchase decisions. They need it as impulsive as possible. So annoying things like 2 factor authentication, in their mind, might make a customer give up their purchase.

So things are insecure because that's what customers want to satisfy their relatively low attention spans and impatience. And the retailers optimize for that.

Post reply on HN