Jb’s story about how he nearly lost his Twitter handle
d.pr
d.pr
If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security."
Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them.
The linked page says to hide your whois information. This is surely security through obscurity. Yet it can vastly reduce the number of reset emails you get.
[1] You should treat crypto like a mathematical problem.
If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say:
"OBT-125, please read number on display."
You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me."
Phone phreaking is still alive, but, it's not as common as it once was.
"4. Some of the biggest companies in the world have security that is only as good as a minimum-wage phone support worker who has the power to reset your account. And they have valid business reasons for giving them this power."
E.g., "No problem, I can reset your password! The system will automatically contact your registered phone number and email address -- if you confirm both, it resets now, and if you can't, it will send the reset to your new email 3 days from now."
I can't think of the last time I was completely cut off from both phone and email for more than 3 days. Can you? I travel around the world regularly enough (I was in Malaysia in November; I'll be in Rwanda in March), but never with breaks in connectivity lasting more than 3 days.
I don't go wandering into the wilderness for more than a day trip, admittedly... but I'm also pretty sure most other people don't do that regularly, either.
Whatever you think of the state of cybersecurity in terms of encryption, implementation, and user-interface (including 2-factor authentication)...it doesn't seem that the protections against social engineering have developed at the same pace as the increasing ease of accessing public records
Yep. Around the same time I started using a randomly generated 24 digit alphanumeric password generated with an offline computer, I noticed a twin person who looked nearly the same as me nearly started living in my apartment, and asking an awful lot of questions about our supposedly shared childhood, wanting to "catch up".
It was certainly nice suddenly having a twin, but it wasn't until he suddenly disappeared three years later that I realized I should have been just as wary about social engineering as I was about my encryption.
Did your brother move into your apartment? Did you imagine a friend? Are you being sarcastic in a way I have missed?
Hell, getting the last four digits of someone's credit card number might be as simple as pulling a receipt they threw away out of the trash.
To be fair, this could render the security question useless. If you lose the password (by losing the password safe), you've also lost the answer to the security question. So a properly backed up password safe renders a security question pointless (or the answers to the security question should be stored in a separate, equally secure, location).
My password safe is stored at many different location so that it's extremely unlikely to loose them all at once. And to secure against amnesia or being-hit-by-a-truck, you should give the passphrase to a person you trust 100%.
These security questions are made for us old farts, for days when there was no Internet like today and there were none of this information available online.
Companies should allow security-conscious customers the ability to opt out of this attack vector. Alternatively, just use another 20 character randomly generated string for each of the answers.
I remember the names of exactly two teachers from high school, today, but only because I was discussing something about them with someone else who remembered over Christmas. My mother's maiden name is spelled differently on her birth certificate and death certificate, so I can't tell which one future me might use after forgetting a password.
Recently, I've noticed a trend of having 6 or 8 fixed security questions to choose 2 or 3 from, none of which actually apply to me in a reliable way.
There's really no other solution but to treat them as an additional password field.
Still pretty terrible, though.
Good to know all they require is that you can guess a 2-digit number instead...
Where's the "reset security question" option...
"Make back ups" is easy to say, but keeping the passwords and access credentials safe is tricky.
The only time I needed my security question was when changing email address on PayPal. I gave them a call and was able to change it by reading the security code (a randomly generated PIN).
Any company giving access to your account by security questions is not to be trusted. I never keep more than a few euros in my PayPal account for multiple reasons, and this is one of them.
Shameless plug to a post I wrote on security questions: https://lucb1e.com/?p=post&id=65
Unfortunately some services have the annoying habit of randomly providing multiple choice for these (ex. TradeKing). So my qgwpagprgqrgwasr2q really sticks out as an odd answer for my first car, making it even more guessable than the real answer.
There really needs to be a way to completely opt out of these systems for competent consumers. I'd never need a password reset, so they shouldn't allow it.
Every single customer-facing company needs to have STANDARDIZED security/information protocols. This includes taking in same information, and only giving out the same information. This should solve this problem.
But regardless, a single account may get compromised, but at least you can't feed partial data from one social engineering attempt into another company, which is what apparently is happening more and more because of impedance mismatches with what everyone uses.
I guess if they can't resell it they do it for shits and giggles, and because grabbing a low numbered/low lettered anything these days is a decent trophy to have.
They could easily put their minor SE skills towards hijacking high quality information, but instead they use it to get known for stealing usernames.
Also how do you manage said X number of emails? Do you log onto each one of them, or do you forward all emails to one "master email"? If so, the master email is still the single point of failure.
- Separate, low-balance checking or similar bank account for "routine payments". Larger balances held in other accounts that cannot be accessed / drawn from through normal channels.
- Separate contact address(es) for distinct and more public interfaces. E.g. I and some friends already have P.O. boxes for this purpose.
- There are other instances/examples, but this is enough while keeping this comment brief.
AND HERE IS AN IMPORTANT POINT: Companies that won't let us do this, or even just make it hard, will become anathema to our own best interests.
THERE ARE LEGITIMATE REASONS I don't want all my services and access consolidated under a single user ID and password or other authentication.
Services that push towards "one true name" and "all services lumped together", are -- from this security perspective -- not in my best interest.
I learned years ago about the value of compartmentalization. It seems that many companies have yet to learn that this is a legitimate concern and feature for their customers.
In the age of electronic recordkeeping and processing, it really is a minimal burden upon a business to support more than one account per customer. Customers have legitimate reasons for doing this. Get over it, and give them what they want and need.
We started embedding a secondary “password” in some of our email addresses, by leveraging googles username+tag feature. So something like johndoe@gmail.com becomes johndoe+1bayjdh1x91nj12e@gmail.com
One less piece of guessable info.
This way, if a hacker gets your LinkedIn profile, the information there is different than your Facebook info, which is different than your Twitter info, which is different from your. .
Imagine a hacker with a handful of accounts and all the information is completely inconsistent. How does he decide which one is real and which one's are fake? It's essentially a dead end and will hopefully get them to move on to an easier target.
Kevin Mitnick always talks about how social engineering is the key usually, ans it is. he used to make phone calls after dumpster diving and gaining employee names. There's no need for that now, we have all our information on the internet.
let me explain a little better. Take your facebook for example. Most people have the email they use on their for everyone to see, same with linked in. Now once a hacker finds who they want to target, just start googling the person and collect as much data as possible through comments made by and towards them. usually they'll comment on their pets name and all the other info they usually use to reset passwords. adding the person on a fake account acting like one of their friends with a new account is typical.
once they have all this info and the emails you use, time to take over what emails they can with your information. security questions are usually the route they go. once they have an email account, time to grab the others that are usually linked to each other for password resets. once those emails are taken over... it's all downhill from there.
best thing to do is make everything private and don't use the same username or handle on everything because that makes it easier to link to you.
just my thought about how this is done. pretty simple if you have some time to invest
The idea that these companies would rather cater to individuals who are careless with their accounts than uphold the sanctity of the majority of their users' identities is deeply troubling. The thought of a dispensable, minimum wage worker being all that stands between me and total calamity is terrifying.
I've already started using 1Password but I'm now considering closed some accounts and calling some of these services to ensure they never give out my information for password resets and such... Scary stuff...
You should be using two-factor authentication for all your AWS accounts, especially the 'root' account that's tied to your regular Amazon.com login (I've always though this is a bit odd).
You should also never use that root account and set up IAM accounts for yourself and any other user (which also use 2FA).
If the service you're using doesn't support it, ask them to implement it. If enough people did it..
I'd still prefer the TOTP approach though because it doesn't require any connectivity on the phone.
Pay-as-you-go phones are advisable to use for two factor verification, as they are affordable and could be used only for this purpose. Don't hand out the number and you've got a nice disposable tool for protecting your accounts.
These articles really make me want to set up an automated system that would monitor any password reset events (and other suspicious activity) and automatically change those passwords itself and/or notify me by sms...
Also, in the source:
<meta property="article:published_time" content="2014-01-29T01:49:03.309Z">They need some kind of back door to recover their access (because honestly, even for the responsible and tech-savvy users, sometimes sh!t happens... e.g., my password manager generated a new password but my laptop crashed before I could save it), and they assume there will be a way to restore their account.
I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers.
A) Customers locking themselves out of accounts
B) Accounts being stolen by identity theft
Pick one.
> I'm sure you could tell your customers "you get what you deserve", but not if you want them to remain customers.
I kill people for a living. You can tell me I could stop killing people for a living but then I'd stop having customers. Thus it's impractical to stop killing people.
Please continue to call common fucking sense idealism. Look how shit any other site besides the 4 (and others like them) I mentioned are with their fancy policies. How can anyone not rage when such stupidity is forced upon us?
How well any policies are actually thought through is another matter.
The problem is not so much that the systems suck, the problem is there's no way for people like me to take on the responsibility and "risk" of just having a simple way to authenticate myself.
For example, in my bank I would opt into having all "suspicious transaction" types of protections turned off, but if I went to my local branch and asked for that, they'd just get confused and think I'm trying to commit fraud.
> it's still better to keep them on board and making money
Maybe better for you, assuming there would be a net loss from turning off the bullshit policy. Definitely not better for customers, as it enables theft, which has the same consequence as forgetting a password.
I have a good backup system so it's not that I use such stuff personally either.
Well yes, I would much prefer that to sending in a picture of my drivers license, only logging in from one IP address, etc. This only really happens with financial sites.
For normal sites, before there were captchas, they required email to sign up, in order to deter spam. Then when they got captchas they still required both, probably because they were thinking "oh yes 2 is better than 1", even though email verification does not deter spam one bit these days. On the other hand, in more recent times you now have all these sites requiring email for recovery. You can see where the dogma came about.
I myself would absolutely never want email recovery, simply because it links the accounts together unless I make a separate email for each, wastes my time (I never lose my passwords, and they are unique for every account), and now the email provider has access to my account.
If this isn't bad enough, facebook, google, and pretty much every mainstream email provider now require a cell phone to sign up, and sends a verification code to your cell (this may be because I use tor).
It only seems to be going downhill. There's no reason not to be infuriated.
On the upside, South Korea recently abolished its law that users should use their id online:
http://online.wsj.com/news/articles/SB1000087239639044408290...
... but it's replaced with SMS:
https://en.wikipedia.org/wiki/Resident_registration_number#O...
https://news.ycombinator.com/item?id=7141532
But they're both pretty much the same problem. Service has complex/secret authentication policy, so users have no chance to be secure.