7 ms·
It always amazes me that someone is hired to implement strong security and they come up with things like paste-blocking. Or "security questions." Security quest
by simbalion 10y ago
It always amazes me that someone is hired to implement strong security and they come up with things like paste-blocking. Or "security questions." Security questions are a social engineers best friend. Unless you're savvy and your answers are all strong passwords themselves, and if they are you're probably using keepass or something like it with 400+ bit passwords and you hate wasting time on security questions too.
- chjohasbrouck 10y agoIt's amazing to me how insecure email is these days. If you know somebody's email, and you have a plausible reason to have a conversation with them, you can very easily take over their email account and reset the password on every account attached to it. I often wonder how much the security of email (and by extension, every other account online) depends on people just not knowing how simple and easy it is to break into. If everyone knew, we'd be living in chaos right now, right?
- Twisell 10y agoThis exactly why all my e-mail passwords are at least 18 character long with random generated gibberish stored on a keychain... And to secured that keychain I use a very long login password (XKCD style + numbers) that always make people cringe. In return I assert a well deserved facepalm when I see a friend log in on his e-mail account with a variation of "Password1".
- oolongCat 10y agoThat sounds like a very tedious thing to go through to login to your email. Just use a strong password ( https://xkcd.com/936/ https://xkcd.com/936/ ) The funny thing with having email as a username is, how sometimes people can use social engineering to gain control of your account, non of that fancy "hoaxer" stuff are needed when your service providers put untrained people in charge of your accounts. Hacking human stupidity is a more effective way in to get in to a secure system. ( as an example, this was on reddit just yesterday https://www.youtube.com/watch?v=lc7scxvKQOo https://www.youtube.com/watch?v=lc7scxvKQOo )
- Twisell 10y agoNope I mean I kinda never login to my mail through unknown browser. My smartphone is just good enough when I can't access my computer, so there is only three places where my long e-mail password is stored. Keychain on my computer, keychain on my smartphone and backed up encrypted keychain in my cloud account. So it's highly unlikely that my e-mails get compromised. Also worth mentioning my e-mails are not hosted on gmail or any big cloud player. I actually pay for my imap, when you don't pay you probably in some way are the product... Paranoid? Maybe Safe? More than others
- bbotond 10y agoCould you give an example of how it is possible to take over an email account just by having an e-mail conversation with the owner?
- boznz 10y agome: Hi Mate, what is your email password? email recipient: Pasword123 me: thanks. JOB DONE :-)
- bbotond 10y agoWell, I was hoping for something at least a little bit more sophisticated.
- Aelinsaar 10y agoNah... it's brute force all the way down. Scammers aren't brilliant men in dashing suits who swindle bankers, they're assholes who prey on the weakest. The second you do something that doesn't mark you as weak in some way, they don't want you anyway. It's the human equivalent of scanning large IP blocks for basic security holes.
- Merad 10y agoI imagine he/she is referring to how most "security questions" use info that we typically don't hesitate to give out in casual conversation, even with total strangers.
- tim333 10y agoI think if I had a casual conversation and they started asking what was your pets name, where did you go to school etc I'd think it a bit odd. As an aside I usually have to write down the answers I've given in a word doc and look them up if I need to do that stuff as I can't remember which memorable place it was and the like.
- 10y ago
- kuschku 10y agoAnd that’s why I host all my email myself, and have my VPS with no password login (only key auth), and have 2FA enabled for the VPS control panel at the hoster, and have 2FA enabled for any change to the domain requiring a letter to be sent to me.
- Tepix 10y agoYou should use a dedicated server instead of a VPS if you're concerned about privacy.
- kuschku 10y agoWith a dedicated server I’d have more privacy, indeed, but already with a VPS with encrypted data that requires me to decrypt manually by entering a password upon restart via ssh to start the actual email service I gain a lot of privacy.
- Tepix 10y agoWhat type of virtualization is it? OpenVZ?
- callalex 10y agoPlease let this meme die. There are very few people left in the world that truly believe that hypervisors are leaking your pii all the time.
- Tepix 10y agoThere are many different types of virtualization. Most of them use disk images, meaning someone can read (or even write to) your disk without you noticing. Some of them are lightweight virtualizations where a priviledged outside user can run processes inside the VM without requiring authorization or without being logged. How is this a meme that needs to die?
- rsync 10y ago"If you know somebody's email, and you have a plausible reason to have a conversation with them, you can very easily take over their email account and reset the password on every account attached to it." Not if they self provide their own email (by running their own mailserver).
- superuser2 10y agoThe same security question nonsense happens at server/VPS providers too.
- Vexs 10y agoYou can run a email server off a raspberry pi these days.
- nommm-nommm 10y agoNot if you want other people to read your email, its going to go right to their spam filter.
- okletsgoyayok 10y agoWhy is this?
- Vexs 10y agoA lot of spam filters filter everything that's not a common, or is a very new, tld.
- superuser2 10y agoSpammers are the ultimate Sybil attackers. Setting up a useful SMTP server as an individual, and creating a new non-blacklisted identity as a spammer, are effectively the same task. The community of legitimate email providers has responded (quite effectively, and without too many false positives) by making this as expensive, difficult, and time-consuming as possible. Emails from residential modems are not even worth scanning - they are practically guaranteed to be from botnets. Emails from commodity hosting providers are also pretty suspect, because they're very easy for spammers to get their hands on. If you want your mail delivered, you need to send it from IP addresses that don't have those obvious red flags, don't have a reputation for sending spam any time in the distant past, and also have a long-term positive reputation for sending non-spam email. In practical terms, you need to be in the professional mail server administration business full-time (be extremely careful to shut down abusive customers/tenants rapidly, never make a mistake that would let an attacker run an SMTP server on your network, etc.) or you need to pay someone who is, and who trusts you to cloak yourself in their reputation and not ruin it.
- Tepix 10y agoUnited MileagePlus just switched to security questions that only allow multiple choice answers. Some of the questions only have 12 valid answers. Compare that with even a weak password! Unbelievable.
- christianmann 10y agoDid you try editing the DOM?
- ibejoeb 10y agoI got caught by that the other day, too, and grabbed a screenshot. Crazy. Guess I'll pick my favorite artist from their exhaustive list. http://i.imgur.com/DWKiy2a.jpg http://i.imgur.com/DWKiy2a.jpg
- jandrese 10y agoThat is laughably bad. I hope there is some backstop where the system will lock the account hard after a handful of bad answers?
- banana_giraffe 10y agoI respond with a strong password for all security questions. It created a cute incident recently when I had to verify my account over the phone by telling the phone rep that my favorite pet's name was 'o(c:Y^u=86U@4k', or whatever. I'll give the rep credit, they didn't care the answer made sense, just that it matched their screen.
- ams6110 10y agoI do that too but shot myself in the foot on one site. Somehow I did not get one of the three random "answers" recorded in my password manager. And of course THAT is the question the site is now insisting I answer. I have tried a few times hoping one of the other two questions is presented, but so far no luck.
- ryan-c 10y agoI had a bad time recently with one of those when the IVR system tried to verify my security questions. I ended up making farty sounds at it to get it to give up.
- oneeyedpigeon 10y agoI'm intrigued as to how you 'pronounced' that. Did you say "open parens" and "caret", and did they understand what you meant? Also, is having to divulge your password really the best way of verifying your account? Do they advise you to change your password immediately after going through this rigmarole?
- banana_giraffe 10y agoI would have rattled off something like "oh open paren sea cap why colon caret you equals" and so on. Honestly I have no idea if they parsed the sentence, or decided "gibberish from phone equals gibberish on screen .. good enough" They didn't advise me to change my security question, no doubt because the name of my favorite childhood pet isn't likely to change.
- Vexs 10y ago
- morgante 10y ago> Unless you're savvy and your answers are all strong passwords themselves, and if they are you're probably using keepass or something like it with 400+ bit passwords and you hate wasting time on security questions too. The worst part is that some companies (TradeKing) turn these into multiple choice questions, where a password-like answer will stand out like a sore thumb.
- c3534l 10y agoMy school had me sign up for a service that required an 8-character long password containing at least one number, one special character, and a mix of uppercase and lowercase letters. The recovery question was "what is your father's middle name?" No way anyone could find that out or guess an incredibly common middle name. Also I should mention that our school required us to sign up using our school email address as our username, which was assigned to us on the basis of the first letter of our first name and our entire surname. And also the address says where we go to school. Do security consultants just completely lack common sense?
- malbs 10y agoYou're assuming they used a consultant. I doubt it.