BitInstant hacked: What and how it happened
blog.bitinstant.com
blog.bitinstant.com
To be rather blunt you should have better security questions. You should always put in a custom answer, for example I might use the question mother's maiden name and then the answer is "L@J-289098=a9jaosdjf" which I keep in an encrypted text doc or ecrypted note in 1Password.
Not a bad point.
However there's nothing intrinsically wrong with the
maiden name question.
Asking users to enter their mother's maiden name, when you actually think they certainly shouldn't do that, then blaming your customers for having used their maiden name, seems like an odd way of doing it.If mother's maiden name isn't a good enough security question, stop asking it! And we all know it isn't a good enough security question.
Looks like they have allowed users to create their own for quite a while:
We have allowed customers to write their own security questions for over two and a half years now.
http://www.site5.com/blog/s5/security-and-social-engineering...
It's a pain, but I don't trust this "Mother's Maiden name" invention.
Problem is remembering this (and some offline systems have it as well, oh well)
So if you think I'm going to put the actual name there you're wrong. Maybe not +@sfghh#54$=24 but something different.
Sound advice, but... but... but.....
This is his own website using this as a security question!
2) Knowing the answers to those questions shouldn't allow an attacker direct access to the account. It should initiate a password reset via email.
https://bitcointalk.org/index.php?topic=128314.1380
At various points in this thread, people posted saying the company even admitted privately to them that they did not have funds to process orders. FYI their most popular feature, Cash to Bitcoin Address, is still offline - presumably because they have no Bitcoins to deliver. The only indication that they have any funds at all is on the home page of Btc-e.com, which indicates (as of right now) that they have a $475 reserve at the site.
On a tangential note, I hate security questions. I do not understand the need for them, or how they keep anything secure, when the questions they asks are always public knowledge.
Like with most things, security questions create a facade of security. Just like the "at least one lower case letter, one uppercase letter, one number, and one non-alphanumeric character" requirement of some sites: more often than not, the resulting password is "easier" to guess (many people put the numbers at the end, etc)
The dangerous ones such as this allow someone to use the security questions in place of your password. These are less secure than if you were to use your place of birth and address as your password.
Their thought process probably goes something like "we can't have users giving us their password over the phone, anyone could overhear that and they would think it is insecure. Lets have them give us something less confidential instead".
Services like this that require verbal authentication via the telephone should generate a passphrase and email it to their uses upon signup.
Any service that is sensible enough to give you that information will hardly make use of "security-questions" in the first place...
So maybe use real words in the future
If you're going intentionally fuck yourself and your customers over by not using real multifactor authentication (not just "a password and some security questions"), then I don't even know what to say. At this point it's on par with having a startup and not having any on-call tax or legal guy-- the inherent ignorance is almost incomprehensible.
That service (being external from the registrar or DNS provider) seems sorely needed by everyone in our industry because this method of attack is starting to become the standard.
Why should the answer to where me and my spouse met really be where we met? Why couldn't my answer be where Lucille Ball met Ricky Ricardo? Why couldn't my childhood street address be Evergreen Terrace?
Add a layer of security by creating an entirely different alter ego with a whole history behind it, and use their birthday, maiden name, etc, instead of what somebody can look up in public records, or find out from people close to you.
Sure it defeats the purpose of those fields as a secondary layer if you should lose the password (if I lose everything in my password manager I have bigger problems) but at least an attacker has no more chance of guessing those than of guessing the primary password.
A security feature that requires me to lie to maintain its security is NOT a good security feature.
I don't buy the argument that a security system you need to lie on is not a good one. Security is an onion, it comes with many layers you can't assure a third party service easily so you've got to add layers to that onion, even if that means being a liar.
That said security is also a trade off with the lowest common denominator - user.