Congressman's phone password is 111111
gfycat.com
gfycat.com
I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they had "that site" that a few folks visited. Here was how that worked:
Nothing except your body and your clothes left the site, anything you brought stayed onsite (laptops that we brought onsite were left behind / effectively disposable, later you couldn't even bring those, they provided one). All that stuff belonged to the military / whomever you interacted with at the site.
No electronics, cameras, etc that were not previously improved were allowed and you were told you would not be leaving anytime soon if you had something "unexpected or unauthorized".
It was highly suggested that nothing was in your rental car other than your keys, the equipment you needed as they searched the car and the folks would take what they wished.
If you realized you had something you didn't want to in the car it was highly suggested you do not turn around if you are at all close to the location and to drive up and immediately tell them you dorked up and brought something. This was a fairly remote location so the probabbly knew you were coming before you saw the gate and the guards didn't like surprises.
Upon arrival you parked, were blindfolded and driven from the gate to the site, you never actually saw the outside of the site until you were in the building. You were never alone at anytime. Trips to the bathroom while at the site were monitored... in person by a guard with a rifle.
Now all that sounds ominous but everyone reported that the folks there were very professional (not friendly but professional).
The point of that whole story was that even a while ago someone said "any electronics" were a threat and decided that they had to go to extremes to limit their access. Still today I think that was the closest to a "sure" policy.
But at the gate you couldn't see much of anything. So you effectively never saw the outside of the site, and even parts of the inside of the building.
What you could see, where you could go, all of it seemed to be clearly planned ahead of time and it was just what was essential to complete the task.
No comment on the rest / some of it I honestly don't know.
None of the organizations involved share a lot of data / answer questions / you don't ask, and everything is designed around you not knowing.
We outsource pretty much anything to contractors, though.
The "hard" part is really just getting the data off the computer in the first place, which is probably why they don't allow bringing in technology anymore.
I wonder how much of a micro computer could be smuggled in one or two parts at a time, stored in articles of clothing, with the intent of simply saving data to a micro SD card which would be the only thing you need to smuggle back out. You would need to be able to assemble the device without soldering.
I guess the easiest would be to build a digital camera to record the screen or photos instead of trying to plug into the computers themselves which probably have robust host intrustion detection and prevention. Or perhaps if you could just record the digital output of the computer before it reaches the monitor. That could be prevented with some form of HDCP though, I think.
This all sounds kind of like a science fiction movie (or In the Line of Fire or that Snowden movie) but it's an interesting thought exercise in any case.
Pure speculation: I have to imagine they take further steps now as what is "no electronics" now isn't reliably what you can easily see now.
What would that do to, say, an artificial pacemaker? Feels a little, as you say, science fiction.
If you want to destroy a piece of electronics quickly put it in a microwave oven and hit start (also don't expect to eat from that oven later - plastic residue etc if it heats up that much is probably not safe to eat). This will destroy usb keys and storage on them, SSDs, laptops, smartphones and data on them. The only kind of data safe is magnetic type hard drives, but they become less and less common these days.
You could even make a kind of "wand" similar to what guys at the airport have for pinpointing metal items on people. Wave it around someone suspected of having a listening or recording device - job done.
So a bad actor would shield them? The primary countermeasure to incredibly small storage is minimizing the availability of devices that could write them on site. That microSD hidden in a nostril won't be of much use if the attacker does not find anything to plug it.
(regarding OP's story: I was kind of expecting it to end with the spaceballs password in heavy use behind all that physical security, still kind of disappointed/relieved)
So you'd have to pull some sort of slight of hand to manage that.
But I guess the boindfolds also had a psychological effect of "we mean business".
If you lack out a special cabi area for a vehicle, either you are leaving them to their own devices in that area, or limiting the senses of your own staff you put in to watch them.
Finally, it's just a lot more expensive and cumbersome to have a large piece of machinery like that, and more likely to fail. What happens if the engine fails? Do you need a spare now? Using a blindfold as backup means that a blindfold is sufficient, so just use it and any vehicle now works.
"if you black out a special cab area". :/
Is it just me, or does it feel like the SwiftKey keyboard for android has gotten much worse in its autocorrect in the last couple years?
I did a poor / vague job of describing that the blindfold was used inside buildings too. Folks walked with their hand on the shoulder of a guard in front of them from time to time.
Like new a policy, fine leave the blindfold on longer.
Broken blindfold, just grab another.
But say truck with a broken blackout window ... can't go onsite.
Most of the time we worked with traditional commercial customers that while some were secure, were nothing like I described.
Nobody seemed to have any concern with the policies / security.
But yea, same thing with them being well aware of your arrival before you show up.
It was their underground bunk backup site near DC, think it was Baltimore area. Drove up to a guard in front of chain link fence.
The customer was some government intelligence agency (he didn't tell me which one). The machine was in a small room, which also had a printer. To get to that room, you had to walk through a big room full of workers at desks.
Before entering that big room, his escort would press a button beside the door that apparently signaled to those in the room that an outsider was going to come through. That would make some audible signal in the room, and start some red lights flashing on the ceiling. Everyone in the room then had to clear their desks, putting all their papers in their drawers and locking them, and returning the most secret document to their safes.
When all that was done, everyone returned to their desks and then someone would open the door, my friend's escort would tell him to not look around, and would escort him through to the room with the machine. The door would be closed and locked, with my friend and the escort in the machine room, and my friend could work on the machine. Out in the big room, the workers would take their work back out and go back to work.
Occasionally, someone in the big room wanted to use the printer in the machine room. Before they could do that, my friend had to be escorted out of the machine room, back through the big room, and out to the corridor...going through that whole "secure the room so an outsider can pass through" procedure to get back out, and then to get back in after the printout had been retrieved.
Unfortunately, my friend had a lunch that day which disagreed with him somewhat, so that afternoon there were also a few times he needed to get to the bathroom, which of course required going through the big room each time.
Of course, i know this because this is old stuff - at least around here. Both protections and banking malware advanced significantly since .. oh, say 2010.
But since banking malware is typically focused on countries, it might be different (less obsolete) if you're not in NW Europe.
If the numbers were scrambled, I'd have to pick a new system to select a password.
And honestly I set it to the same, just because it's the most convenient to use. If I make a convoluted pattern I won't be able to do it as easily.
So still same old crap.. we tend to go to thinks we can remember and easily do- and that is not the most secure.
First initial probably.
> honestly I set it to the same
Hmm. If it's the same, last name then? Maybe a diamond or something. I heard (Mitnick's book about best practices called The Art of Invisibility, chapter 1) many people don't use the corner dots very often, or they use an initial of their name.
I unintentionally can see people's phone patterns when they do it in view. At least with a passcode you can usually try to ignore it, or you have to try to pay attention. Those pattern ones show it visually in a way that's hard to ignore.
"Oh hey, cool, a Σ!"
[0]: https://helpblog.blackberry.com/2014/02/how-to-use-picture-p...
In reality a lot of iPhones now require authentication at the app level for apps that have sensitive data.
To each his own, but knowing how public you are and how many people would want your passcode, I think the best practice is to use something dumb like 6 of the same keys.
I'm fairly certain that knowing my passcode would provide access to my email, which can then be used to acquire access to plenty of critical services.
The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.
If you process the feeds for public transit security cameras, I wouldn't be surprised if you can read the pin codes for a huge swath of the population. It would also reduce the need for law enforcement to try to get a suspect to tell them their passcode. Just look up that time they rode the subway 3 weeks ago and watch them enter it.
A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure.
Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN.
Oh dear.
While generally true, this is probably not the case for someone who's regularly using their phone on camera like a Congressional rep.
It's just security theater.
1234 1111 0000 1212 7777 1004 2000 4444 2222 6969 9999 3333 5555 6666 1122 1313 8888 4321 2001 1010
https://www.pocket-lint.com/phones/news/148224-these-are-the...
I'm not using any of this, but many of the people I know their PINs (family, girlfriend, close friends)
Are actually using something from this list
"What this process appears to show is that Apple never sees, handles, or stores your device passcode or password in unencrypted form, and it never passes the passcode or password over anything but secure transport. It requires only your Apple ID account name and password, sent over HTTPS, as the first stage of logging into iCloud, but not for the later stages."
Excerpt from: https://tidbits.com/2019/09/26/why-apple-asks-for-your-passc...
So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a home button (I think iPhone 8) or 4) Become and Android user.
I think it would be helpful to understand your use case and how you balance your personal tolerance for risk and consequences so we can better consider users like yourself.
I have an older phone that is basically a home remote for various things. There is no reason for it to lock, it would be annoying.
I am of an older tech generation who sees this type of security as antithetical to anonymity.
If only I can find a smartphone for talk/text/web/GPS, I'd be switch in a heartbeat. I'm seriously getting sick of the all the security features that tend to bloat the device and slow it to a crawl.
That being said, if my phone was vulnerable to theft or I wasn't so careful, I would lock my screen.
I primarily use it as a camera and tape recorder. And mobile wifi web browser with retina resolution in rare cases, all in which I specifically avoid using it to use any sites that require logging in.
I have a fake name on it. There are no contacts or email accounts set up on it.
It's not ever been activated as a cell phone.
Basically, I see no reason to have a password on it, and a password slows things down slightly and has the risk of forgetting (since I never reuse passwords), so why bother.
My Android phone that I do use as a cell phone though I have a password on it. It has similarly few personal details, but the call logs would make it easy to identify me.
Granted the iPhone's location logging though disabled might be storing info anyway, and probably the photos are GPS tagged, so those things would identify me.
I think the argument hidden in the headline here is that since this is a device owned by a congressman, and allowed inside this particular meeting, it has information on it that may be confidential, and therefore needs a much stronger password.
My phone has access to my email, phone number, texting.
With these 3 things you can get into my bank account, access to my domains, and into any online account I hold.
Then, personally and professionally, I manage other peoples' accounts, so, with my phone, you can probably social-engineer your way into those as well.
My point is, if you are married, have a job, email, or have other people in your life that you don't want to go through an identity theft crisis, or get hacked, stalked, etc, you should lock your phone.
Maybe you aren't the target, but you are the wide-open back door into their life.
I don't manage other peoples accounts from my phone.
My passwords are stored in an encrypted file, accessible only by entering my pin.
My email app has a pin lock.
I don't use the browser to login to any important sites like banking sites.
If you get my phone, the most you can do is order something for me on Amazon (it will be shipped to me, else you have to enter your own credit card) or you can mess with my GitHub content.
Considering that both your password and email are protected by pins, why not have a pin on the device too?
Someone installing an app to catch pins that I typed in and then giving me back my phone...then waiting until I typed a pin and stealing my phone again seems like a bit of a hassle. Out of curiosity though - what app in the app store allows you to do this? Or, do they have to jail break my phone to do it?
I'm not really trying to argue that my way is better. I'm just giving my personal point of view. It works for me. I just don't worry about things and shit seems to work out. I leave my house unlocked all the time. Same with my car. I leave the keys in the car when I go into stores.
It's just stuff. Perhaps if someone stole everything from me, I'd be even more free than I am now.
Why would you have to steal it again?
> Or, do they have to jail break my phone to do it?
They will most likely have to jailbreak it.
> I just don't worry about things and shit seems to work out.
Yeah, sure, nobody ever said it happens often, it's for the time it happens that it save you so much trouble.
A friend got his credit card stolen recently, no big deal, I'm in Canada and the bank take all the blame in theses cases. It still was way too much trouble to get a new card because the guy changed his card information and the bank couldn't validate his identity.
It's not always about what you may lose, it's about what may happens to get back from it.
> It's just stuff. Perhaps if someone stole everything from me, I'd be even more free than I am now.
I don't believe you, but good for you if believe it yourself.
This would also have the positive side effect of making it really hard for public employees to engage in corrupt and illicit behavior (which, as we all know, is so rampant that it's practically industry standard at this point).
You don't need a passcode or facial recognition to access any phone that doesn't have those features enabled.
If you enable them you certainly do.
> I don't lock my phone at all. Never have. However, with the new iPhones that don't have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked.
And I'm saying that you can use it without those features enabled; even on iPhones without a home button.
Also, while it might not be too difficult for someone to figure out my phone number and/or email address from my name, it's not like there's a public directory of either. "Not secret" does not should not equal "public".
I'm curious what affect not locking your phone might have on police reports if your identity/etc is ever stolen and you need to provide police reports. Possibly nothing, but I can imagine some credit cards legal team working hard on that aspect of things in the event you're trying to convince AMEX to return $40k of transactions you supposedly didn't make yourself and need reversed because your phone was swiped while logged into some CC app and they copied your card number.
That's what made him fine, not the fact that you didn't lock.
That's a thing that quite misunderstood, but for a crime to be committed, you need criminal intent. If you just made a mistake and weren't aware it wasn't your house, it's not a crime to enter it.
But that's also the thing- we had no idea what his intent was. I do recall the police that night seeming less concerned because the door was unlocked and I was chided quite a bit. I do recall them telling me what I said in my initial post but I also understand criminal intent. Personally I'm glad the guy wasn't wrung up with a felony if he was just on some ambien sleepwalk bender or whatever he was on.
Also for some crimes the intent needn't match the outcome. For example in the UK _Attempted Murder_ requires (as well as facts of an attempt) you had an intent to kill, but _Murder_ only requires that you had an intent to at least cause grave harm, the fact of death makes it murder, even if a jury believes you intended only, say, to hospitalize the victim.
That said, I have a really good friend that chooses not to use a passcode for their phone.
Somewhat irritating because being a really close friend we sometimes have very personal conversations via text, and the fact the they don’t lock their phone means I have to be conscious of that. These aren’t deep-dark secrets, but still personal things I wouldn’t share publicly.
Anyway, many years later after I started, IT hires a person who wants to do good while in IT. This person discovers the CEO is still using the day one password he was given. The IT person decides to email the CTO, the director of IT, and the head of HR warning them the CEO is still using his default password.
I’m not clear what exactly the wording was, but the IT person skipping over the chain of command was bad enough it got them fired.
Isn't this roughly the opposite of what you want in an org? Otherwise there can be the failure mode of only good news getting reported up, so the folks running the company base their decisions on finely cultivated bullshit and are completely isolated from reality.
[0]https://www.stigviewer.com/stig/apple_ios_8_interim_security...
DoD and ASD still don't like biometrics, in ASDs case because the want to see how it works: https://www.cyber.gov.au/publications/security-configuration...
Biometrics like iris scanners and palm prints are used everywhere for high security govt installations, but I guess they have been tested by spooks.
I wish LineageOS and stock Android added that feature.
Asking "How secure is this?" is essentially the same as "What angles of attack would this prevent?" So if your phone is susceptible to a very basic dictionary attack (which is just a codified way of saying "susceptible to educated guesses") then it is not "just as secure as any other code" because there are other passwords which aren't susceptible to this attack.
Note that my post was responding to the claim that it's "just as secure as any other code". It is not.
If you myopically only look at the most basic of attacks, then you can use crap security and it will work for those attacks. But a US Congressman could obviously be a target of sophisticated attackers. And you're literally proposing an attack which would break your proposed password, yet still defending the claim that it's just as secure.
I was just reading someone's comment saying they come to HN because the comments are so good, and I can't say I know what they're talking about. So much uneducated speculation about comments taken out of context is being presented as fact in these comments.
If you really want to delve into the specific scenario of a US Congressman then there are many more factors like how are you going to get access to the phone at all? How are you going to avoid the lost mode activating? Iphones have limited tries before permanently disabling so how many are you going to risk with a dictionary attempt? Would you really put 111111 as the first try considering most people wouldn't use that?
But what happen when it's a congressman?
We start to see now more and more data breaches that happens due to lack of basic knowledge in this subject....
Just 3 days ago was reveal that Equifax used 'admin' as username and password for sensitive data. ( https://finance.yahoo.com/news/equifax-password-username-adm...? )
In this case I'm sure that the IT person who's in charge for the system just give zero value to data protection and cyber security....
>According to an industry report by Shred-it, 47% of business leaders cited human error as the main cause of a data breach at their organization
https://www.perimeter81.com/blog/network/how-employees-open-...
Leave beside the fact that someone in this position should have better understanding of cyber security
I wonder if they get any kind of training from the government.
I'd get in trouble breaking into the Oval Office even if they put all the secret papers away.
https://www.cnet.com/news/kanye-west-meets-with-trump-reveal...
Here is a Twitter thread about why that is such a problem:
We detached this subthread from https://news.ycombinator.com/item?id=21344785 and marked it off-topic.
The value of an HN comment is the expected value of its future subthread—i.e. itself, plus the sum of the probability distribution of the responses it may receive.
In this case the EV of your post was negative: first because it brought in a partisan stunt that was still hot from the news of the moment; second by framing it one-sidedly ("barged into...without authorization...such a problem"); third by linking to a political source that one side is overwhelmingly likely to agree with and the other side to be unimpressed or offended by.
You're right that the flamewar was more in the responses to your comment than in your comment itself, but that's true of most flamewars. Flames get hotter as they spread. From a fire prevention point of view, the issue isn't where the fire burned hottest but where it started.
By the way, there are some deeper, interesting issues with this 'expected value' model of comments. It implies that commenters are in some sense responsible for the behavior of others and not just what they they themselves post. That's weird. And it implies that one needs to consider not just one's own post, but future replies—also weird. Yet it is the model that works the best in practice.
Although I am still not sure I agree with the general guideline of not bringing up something like that incident as I believe it was on topic to both the post and the comment I replied to. My comment might have been the one to inspire a flamewar type response, but it wasn't the only comment that mentioned that incident in general. That said, I will try to be more mindful of that in the future.
Our communications, privacy, and security, are in good hands! Ugh.
Phone passwords are for protecting things from your family.
I think Apple and the FBI disagree
https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
I think what you actually mean is anyone who has physical access to your phone. If you lose your phone or it is taken by authorities, then you are at risk of having strangers access your data.
If this guy was relying on any password to protect his phone from physical access then he is in for a nasty shock - whatever his password was, his adversaries would know it after this video. That fact that it was 111111 doesn't actually change anything.
He's in the US government. If he is up to something and he has enemies; it will get leaked. If he doesn't have enemies the lack of security isn't so terrible. His work is supposed to all be in the public eye anyway.
[0] https://nakedsecurity.sophos.com/2018/09/06/ungagged-google-...
Generally a random people do not have access to your Gmail account.
The fact that the password is so simple makes it much easier to discern the from the video.
Just because his work is in the public eye for the government does not mean everything he does on the phone is supposed to be open to the public.
That's a bit of a sad, unusual sentiment
Most people aren't; it isn't a feature to protect people from governments (I wish we had more features that did). Encryption is a good thing in a general sense but for most users they are more likely to lock themselves out of their own data than protect themselves from anything outside their close friends and family.
Those people lack education on the topic.
I remarked there's a reason why the key cards are unmarked, right?
It isn't just individuals who can't into OPSEC though. Soon after this conversation, the company created a policy saying you have to pay $10 to get a new key card if you lose your key card.
I thought that was stupid. Now, suddenly you have incentivized people to NOT report they don't have possession of their key card any more. We want people to report the instant they lose access to their key card, not three days later when they have exhausted all options. My understanding is that you can easily reactivate a key card if it is found again and the risk of unreported lost cards outweighs the cost of a new key card.
I also agree with the conclusion (the risk of unreported lost cards outweighs the cost of a new key card).