United Airlines’ so-called online security (2016)
techcrunch.com
techcrunch.com
But, isn't it possible to legislate this on a blacklist basis? "Fine of up to $X if you're storing passwords in plaintext. Fine of up to $X if you're limiting the length of passwords to < 16 characters. Fine of up to $X if you misrepresent your 2FA implementation (as in the article). Fine of up to $X if you accept unencrypted logins over the web."
Outlawing a small set of easily identifiable and correctible attack vectors, would be enough to get companies thinking about security a bit more seriously. It doesn't have to be anything big, and I wager it'd have a serious impact.
That is, don't legislate implementation but consequences.
Prepare the law, give companies 3-5 years to prepare, and after that, anything is fair game. If your company is accepting plaintext passwords there should be something that makes you say "oh we have 3 years to change this, let's hire someone to fix this". If a system is live and in use, it -should- follow some -minimal- standards for security.
That doesn't preclude your data breach fine idea - that'd be useful for more advanced security situations that can't be predicted (as you said, based on expert opinions).
But something as basic as "you're not allowed to pretend it's 2FA if it's just password + questions" or "you're not allowed to store passwords in plaintext", that sort of thing should be the minimal baseline that companies should have to adhere to, surely.
Insurance premiums of all types are based on risk factors, so the policy would be written against a checklist of best practices.
Similar to how having a fire extinguisher in your kitchen reduces your home insurance premiums by small percentage, the same could be said for each security practice. Encrypted passwords: -2%. Mandatory 2FA in place: -3%. Etc.
United began debuting new authentication systems wherein customers are asked to pick a strong password and to choose from five sets of security questions and pre-selected answers.
This has been in place for 3 years despite public shaming.
Edit: oh yeah, I forgot, it also doesn't recognize case sensitivity. A = a
I'm assuming they're storing them in all caps, 8 character length database fields on a monstrous ancient mainframe software application.
But hey they require security questions!
It’s 2019, how can this be...
I have problems taking any security advice seriously from such companies after that but since I fully expect them to use ut against me if I ever have to file a fraud complaint I guess I'll have to deal with it - and get another account with a company that isn't braindead when it comes to security.
Not to excuse such password schemes - they're horrible, and banks need to get with the times - but if they were really so ineffective, their coffers would have been drained long ago.
Maybe think of it like this: imagine that you have an airgapped system where all the endpoints are running Windows XP (reasoning being something like hardware drivers that were written by defunct companies and can't / won't be upgraded). Is it horrible that such machines are running unsupported, EOL versions of Windows? No question. But if there are other controls in place (like airgapping, like 24/7 physical access control to the endpoints), it might still be possible to provide de-facto effective security.
Do you have a source about the plain text passwords claim? I won't even be surprised if that's true.
Well that was the worst place the author could have mixed up authorization and authentication...
In fact, he seems to use authorization and authentication pretty much interchangeably, which kind of undermines his rant a bit...
There needs to be real, material damages for companies who do not properly secure data following best-practice guidelines. Not just a 'oh sorry your account was compromised, please change your password!' circus - actual, concrete damages by way of fines or the like put on those who do not properly look after user data.
I know they have fought quite a bit of mileage theft out of a number of countries and they thought this was a good idea of doing that but it's awful.
Or I am just extremely naive?