Let them paste passwords (2017)
ncsc.gov.uk
ncsc.gov.uk
It's not the flavour that makes you fat.
Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance. An element of punishing oneself for past transgressions seems essential.
Security people have the same mindset. Security must be a hassle. It must be in your face. It has to be onerous. A challenge. A hurdle to get past.
I've tried, over and over, to explain to my customers that often the slickest, most hassle-free approach is the most secure. But this almost never sells.
Meanwhile, I see vendor after vendor successfully selling products that exist only to irritate users.
What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle.
This is the UX I really like for WebAuthn / U2F.
All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phone for example you tap the same fingerprint sensor that would ordinarily unlock the phone. Short of not having a second factor at all it couldn't be smoother.
But if this is actually a phishing site or you're a crook who doesn't have the hardware token, it just doesn't work. Still low friction in a sense, but low friction failure. There is no way forward, no override, no "I'm sure", nothing - it just won't work.
Your phone got stolen or smashed. Your 2FA is just not available. Welcome to the sea of hassle proving your identity.
But a little bit of hassle beforehand, in the form of printing one-time codes and storing them even in your wallet would help dramatically.
I'm far more likely to lose my keys or wallet than 2fa.
It's an unhelpful generalisation. There are many jobs that could come under "Security people" and they work under different requirements.
Many will agree with you on the hassle-free experience. There's no need for the us-vs-them.
#!/bin/bash
sleep 2.0
xdotool type "$(xclip -o -selection clipboard)"
If a website prevents you from pasting stuff just type "paste" and then click the field and wait 2 seconds.Take this one: https://systemschimb.telekombanking.ro/login - enter a random user id, and behold the password input field:
- all characters are separated (not one password field, but 10-15 ones)
- some characters are randomly grayed-out (you're not supposed to enter all the characters of your password)
Using a shared secret in addition to a salted password is probably acceptable, although how much extra security it gives is debatable.
(if they ask for 2 characters, assuming a-zA-Z0-9 you're talking maybe 4k permetations, and then you know 2 characters)
A 10 character 64 symbol phrase would take 64^10, or 1e18 guesses
5 lots of 2 characters 64 symbols would take 5*64^2, or 20k guesses
And all this to protect for keyloggers. Probably a hardware token second factor is more effective.
They then loose me as a customer, and everybody else who I can influence.
It was (is?) common practice to have a visual keyboard to enter the password in extremely sensitive applications like banking. This prevents the password from being captured by keyloggers and from being saved by the browser, because malware automatically extract and collect these, which was a very real issue with banking.
We did something similar for call center caller authentication (you don't want the operator to get the whole PIN of the user, so he asked only for e.g. two characters). Not that this would be very useful, security-wise.
Wouldn't this be way easier to crack if the password hashes were leaked? Once you crack one 5-letter hash, you can trivially crack the one that shares 4 characters with it, and do that repeatedly until you have all 10 characters.
You're reducing the effective search space not by a factor of 252 (8 bits of entropy, which would often be acceptable) but to its square root, losing half of the entropy.
Although it seems like security theatre, the PIN solution actually sounds more useful. The typical attack on a system protected by PINs, like bank cards, is not cracking hashes offline - it's that the attacker tries the PINs on the live system and gets locked out after a small number of failures. Assuming the bad actor can't just initiate another call and ask for the other two digits.
Other risk-related fields typically have at least some of the same issues. Risk avoidance is always a no-effort strategy, and the industry is full of people who rely on it entirely, because they don’t have the skills to implement actual mitigation strategies.
Pretty much in all circumstances the outright adversary is Enterprise Architecture or Security using governance and security to push complex standards that don't work and result making changes harder and unpatched systems.
Some of them are receptive if you communicate the issues in terms of risk, but many most in my experience are only receptive if put it in writing and you copy in their boss.
It can use a different key combo, or automatically be chosen when pasting into secure fields
It's not about any penance, you got it all wrong, this is about our brain going haywire for food high in calories.
"If it tastes good, spit it out!"
It's not an absolute rule obviously. Generally products masquerading as health food that taste "good" are loaded with sugar.
Big side-tangent, but amusingly enough, one modern view on the etiology of metabolic syndrome is that your brain tracks satiety for different nutrient classes separately; so foods that are "tasty" in the sense of containing many different nutrient-signals (sugar, salt, fat, acid, etc.) take larger quantities of food to signal fullness (something something liver metabolism is a rate-limited queue); so if you start off hungry and eat such foods until you "feel full", you will have eaten more of them than you "should have", to the point of eventually doing excitotoxic things to your leptin receptors, inducing leptin resistance and making you feel hungry more often.
Which is to say, it's not flavor that makes you fat, but rather flavors, plural. ;)
The advice of the scientists who subscribe to this hypothesis is that you don't have to eat bland food; you just have to eat monotonous food (food only containing one primary nutrient-signal), and you'll feel full with less of it. When you sit down for a meal, eat all meat, or all bread, or all green leafy vegetables. Balance your diet by having something different each meal, not by combining foods in a single meal. Avoid foods that are themselves "combinations", like pizza. Avoid adding a secondary nutrient-signal to something to "amp up" the taste, like adding sugary+oily dressing to a mineral-y salad. Just choose foods that already taste good to you without any "amping up", and eat those, by themseleves.
This is, after all, the real "paleo diet": when animals kill prey, they eat just meat for a meal. When they find fruit, they eat just fruit for a meal. They don't bring them together to eat them all at once.
(Whatever you think of the hypothesis, studies have been done which confirm the advice: eating monotonously per meal, makes you feel full after less food intake. You hit a wall with a kind of "tired/bored of eating this, disgusted by the idea of eating more" feeling, which makes you lose the rest of your appetite. That's your body's nutrient-satiety mechanism kicking in correctly.)
I’ve dieted now a few times quite successfully while living with a chef roommate.
He cooks amazing meals. Salads with more ingredients than I’d ever bother to use, stuff like that. As a chef he really puts time into hitting many flavors (not always, but often).
I’ve never had an easier time losing weight than this last time! Down to my healthiest in years, and been super happy with how easy it’s felt.
Here’s a theory: I’m getting a lot of happiness from eating delicious food. If I eat bland things, sure over time I may adapt to it. But to be honest, getting joy out of eating is one of just two things that is an inexhaustible source of delight for humans. Trying to diet and deprive yourself of flavor is like fighting two dragons at once.
The dopamine/serotonin balance I get from a well crafted, layered meal is actually what keeps me satisfied and feeling like “I had my pleasure, I owe it to myself to accept that as enough”. A fun diet is easier to follow.
Edit: just to add. I also get a ton of happiness from cooking new and interesting things. To me, the craft of cooking also helps mentally. I get satisfaction from trying new things, being creative, pleasing my SO, etc - humans need some amount of creativity and play. By fulfilling that through cooking, you avoid seeking it in eating. I’ve noticed clearly when we make a nice meal I’m so happy at just having done something well, my dopamine is low once it’s time to eat.
I think you're arguing with the GP comment, not my comment. The kind of "diet" being described in my comment above—if you even want to think of it as a diet—doesn't actually stop you from eating anything, if you count by "flavor experiences" rather than "meal experiences." It just makes you get your "flavor experiences" separately, rather than all at the same time. (Or "as separately as you can." A food with N-1 macronutrients is still going to fill you up faster than a food with N macronutrients; so just minimizing macronutrient variety per meal is fine. You don't have to strictly limit yourself to some small number. Eating a salad with dressing as your meal, is still better than eating a salad with dressing and meat in it.)
Most foods invented throughout history actually already fit this "diet." Vegetable soups, however many ingredients, still have only two or three major macronutrients. Roasted poultry only has one. Mashed potatoes only have two. A steak has one. Fruit pies have three. Nigiri sushi has three. Most authentic italian pastas have three. Even "bad for you" foods like hot dogs or mac-and-cheese only have three, if you make them from scratch.
There are two types of recipes that have high macronutrient variety: those invented throughout history to be served to nobility/royalty, that were "fancy for the sake of being fancy"; and those invented in the modern era of year-round grocery-store ingredient availability (and thus no need to work with what's in-season, freshly-harvested, before it rots.)
Sandwiches, hamburgers, American pizza, "tex-mex" tacos/burritos, and other food-court staples: nine or more macronutrients each. The kind of cheese powder found in doritos or shelf-stable mac&cheese counts for eight by itself! The average take-out order of "American Chinese food" hits almost a dozen. Most French sauces reach seven macronutrients on their own, before counting what you're putting them on. A full English breakfast has twenty macronutrients.
Some of these are capitalism at work, creating ever-greater superstimuli out of originally-simpler meals (e.g. pinche tacos; authentic regional Chinese cuisine; etc.) You can just buck that trend, and be healthier for it.
But for some of the others, the macronutrient-variety is fundamental to what the food "is." In those cases, keep in mind that most of the food experiences these foods give you, are made up of—"synthesized" from—simpler standalone food experiences, that just happen to be happening at the same time in your mouth, without really being one unified food experience. You can have the experience of eating just the "melty cheese" part of a pizza—that's raclette. You can have the experience of eating just the meat part of a hamburger—that's a hamburger steak. A loaded twice-baked potato breaks down into two separate meals: baked potatoes + sour cream, and a pasta-salad-like dish. Etc.
None of these are "less tasty" when taken separately. They're just different ways of having the same experiences. If you like, you can eat garlic bread for one meal, a Greek salad for the next, and charcuterie for a third—and you'll have "eaten a pizza" of whatever toppings you like. (Personally, I'd rather just eat a simple caprese pizza, which has ~5 macronutrients; but if you prefer the complex flavors, go ahead and have them. Just—separately.) Likewise, if you're getting American Chinese take-out, you can just eat one of the dishes you ordered per meal, rather than trying to have a little bit of all of them each meal. (Some of those dishes are, individually, pretty macronutrient-rich, but if you want those flavors, this is how to get them.)
Of course, you can have complex foods if you do it as an indulgence, the way people think of ice cream (which is actually not an indulgence under this paradigm; you'd get full on a meal of pure ice-cream quite quickly, if you were just eating from hunger, rather than stress-eating.) You'd just have to be consciously aware that your body isn't going to correctly estimate when you've had enough everything-pizza, and so you'll have to consciously limit your intake rather than relying on satiety in that case. You'll likely end up somewhat hungry after such a meal. That's fine—you'll get to feel full again soon-enough, as long as your next meal after that is a low-macronutrient-variety one.
I'd argue that the simultaneity is a new experience though. Just as playing first the low notes and then the high notes of a musical score sounds radically different than playing both scores at the same time, the taste of pizza is exactly the interaction between cheese flavour, bread and topping.
The theory about satiation sounds plausible and I can easily imagine that you will eat less by consuming only monotonous meals, but I'd disagree stating this would be the same experience are being similarly enjoyable.
Also your examples fit my experience as well. A hot dog is best with some mustard, relish, maybe grilled onions. The bread has milk, sesame seeds often. The hot dog itself is seasoned with a variety of spices.
and,
b) This reminds me of Penn Jillette's potato diet, and might explain why it works.
> write passwords down in places that are easy to find (like post-it notes next to the screen)
Writing passwords on post-it notes is often used as a ridicule of non-tech-savvy folks behavior. I'd like to pose this question: If you're doing this not at an office, but at home, is this really so bad?
Say you run a web site on AWS and write your really long AWS password on a piece of paper at home. It would take a hacker finding out where you live and breaking into your house to find the piece of paper to access it. On the other hand, your ordinary neighborhood burglars typically care about cash and jewelry in your house, not post-it notes with passwords. It seems those two categories of intruders rarely overlap, unless you're a world famous target.
Password is mayfly-DyHpE82sd3r3rvr!2sDQ
Part you write down is DyHpE82sd3r3rvr!2sDQ
But in many cases when you don't live your life online and login everywhere with your Google account federation - sure write it on a post-it. It's not good enough though if you have 20+ accounts and would make you share a password between them.
Yes. Keylogger and Webcams and untrustworthy roommates/family members/landlords are all low threat but; This encourages people to use the same password for multiple sites/services so as not to get overwhelmed by sticky-notes. So whenever one of those are breached, your email:pass combo becomes public knowledge.
I hope this is a peek into the future of government communication everywhere.
(For the pasting, I agree with you. I can't think of a single reason I'd want a website to prevent me from pasting)
There is also a version for Chrome: https://chrome.google.com/webstore/detail/dont-fuck-with-pas...
EDIT: Made the link locale independent and censored the name better.
Paste as Keyed Characters types in the contents of the clipboard for you [0].
Paste AlphaNumeric Only will only paste in letters and numbers from the clipboard [1]. Very useful when pasting contact phone numbers into forms that only allow numbers.
My theory is that security is the least desirable part of the entire software engineering stack - it’s boring, has a lot of blame and liability potential, and it’s a cost center. Heck at least infrastructure folks get to brag about things like cost optimizations.
As a result it seems to me that security attracts the kind of people who view it as a way to wear a digital uniform and badge.
CISSP will have you learn the required strength of a light bulb to light the alley behind the office. OSCP will introduce you to overflowing a buffer and pwning a remote service...
I know which one I find preferable to learn :)
This is my hammerspoon config that lets me do this, it's like 7 lines but could just as easily be 1 line: https://gist.github.com/philsnow/48ae8a31f7e063b23d4013470f0...
Benefit: works across all browsers, even daffy embedded (electron) ones where it's inconvenient to install extensions.
[0] every browser extension you install that has a broad permissions manifest is a liability; when they get popular, the authors start receiving offers of money from sketchy people in exchange for adding 'extra' bits of JS
And by attempting to plug that hole you've added an inconvenience that may encourage users to use a less secure password.
And that’s not even touching all of the government websites that behave in this way.
const q = document.querySelector;
q(‘#password’).onpaste = e => e.preventDefault();In this era of information technology everyone is bombarded with tons of data that they don't know how to think and memorize
Thinking and memorizing can strengthen your brain muscles but people hate exercising their bodies and their brains
I do use keepass for managing different passwords, but I kind of memorize most of them, only open keepass for storing them in case I ever forget
I can memorise af58f916cc0cb22193c18f02d3c1cc3e easily, but once you work out (perhaps a keylogger) why that's my paypal password, my google password of 68b31385067f73977c6007cefcddbe74 falls quickly
Back in 2012, my facebook password was idontunderstandthepointofonlinefriends2011. I don't think it's easy to forget something like that.
I'll admit I'm probably an exceptional case but regular users must have 100 or more password after a couple of years online.
Easy to remember, and you'd have to be very determined to get the link between them even if both were compromised, but if the plain text version was compromised then it would compromise the entire system
That's the most secure system I can think of which doesn't involve remembering thousands of complex random passwords. Sure I can remember "correcthorsebatterystaple", but can I remember which 4 words for which specific site?
When I had to log into this one vpn for work I even used to have it open the 2fa app, click the button to copy the code, open the vpn app, enter all the fields, and log in all from one keyboard shortcut.
You can have the keyboard handle everything
They even scramble the keypad and vary the last 2 bits of the colour, so you need to do an approximate match on the buttons. Still takes maybe 40 lines of python to automate the login.
In theory it's possible that they're trying to do some other thing by handling keyboard input on password fields, and that interferes with hotkeys—but I can't imagine what that other thing would be.