10 ms·
Hackers account for 90% of login attempts at online retailers
- tribune 8y agoThis makes sense given how often they'd fail. When I log in it takes me one attempt. When someone is using stolen credentials they might have to make hundreds of attempts before actually logging in.
- mrep 8y agoThat, and most websites remember your computers forever so you rarely ever need to log back in.
- reaperducer 8y agoI wish. If that were the case, there would be almost zero market for 1Password, Keychain, and a dozen other solutions.
- weavie 8y agoThe ratio is waaaay higher for ssh login attempts.
- JustSomeNobody 8y agoArticle doesn't talk about what they're doing to mitigate the problem. Well, except tell the reader to change their passwords. So are online retailers just hoping the problem goes away?
- mullen 8y agoThe only way I see this problem going away is when regular retailers start supporting software and hardware two factor authenticators. I use Google Authenticator on any website that supports it and it does not impact the customer experience at all and it really improves security.
- QUFB 8y agoAgreed, but keep account recovery in mind. Account recovery is a major pain point for any site that supports TOTP 2FA. If you're not using a TOTP application that supports cloud backup (like Authy), when you lose or replace your mobile device the existing TOTP tokens are useless as they can't be recovered. This results in some type of account recovery process to reintroduce the 2FA tokens. Often these recovery processes introduce additional security issues that are equivalent to not supporting 2FA at all, or they might require costly human intervention. Don't get me started on SMS 2FA.
- drchickensalad 8y agoI'd like to get you started on SMS 2fa. I deal with this a lot at work and would like as much information as possible!
- jandrese 8y agoSMS is terribly insecure. Using it as a security system is a bad idea. SMS verification is more for discouraging bots from making accounts by making it expensive--you need to buy a cell phone. Every SMS verification system refuses to send to VoIP type accounts for this reason.
- jsoverson 8y agoCouple this with the fact that mobile services are also subject to credential stuffing attacks constantly and, for the services that allow you to read SMS messages online, the attackers who take over your mobile account also gain a critical piece of your 2FA protection.
- davchana 8y agoExactly that's why I have disabled my Google email recovery via phone number. Only possibilities are Auth via an existing signed-in device, Google Auth, or backup codes.
- davchana 8y ago
- kevin_b_er 8y agoThey have to balance user attention and user friction. Online retailers want your purchase to be as smooth as possible. There's some studies on how someone won't spend much time on a website if it loads slow. The same can apply to purchase decisions. They need it as impulsive as possible. So annoying things like 2 factor authentication, in their mind, might make a customer give up their purchase. So things are insecure because that's what customers want to satisfy their relatively low attention spans and impatience. And the retailers optimize for that.
- JustSomeNobody 8y agoMakes sense, nobody like slow pages. However, don't most people have the browser save their password? So couldn't the online retailer have some sort of exponential delay (to a limit) after so many failed attempts? Surely that would affect few real customers.
- wild_preference 8y agoWhat is being delayed? Just an IP address or the entire account? Neither really work.
- baybal2 8y agoThis has to do with affiliate schemes. Payouts for them are quite solid. Clickfraud people, I think, count on the the fact that for huge e-retailers, it takes months to take action, and they can cashout affiliate payouts faster then they react.
- jsoverson 8y agoIt's far more than affiliate schemes. Credential stuffing attacks result in account takeovers for many different types of companies and the value that can be extracted is different for each business.
- vxNsr 8y agoI recently joined a website the did away with passwords, the only way to login was to enter your email address and confirm by pressing a link in the email, while this adds a pain point for customers it offloads most security implications onto the email provider.
- swlkr 8y agoI also do this with websites I make. It is a little inconvenient, but it's worth it, assuming the person logging in as a secure way to access their email (2 factor auth).
- dave5104 8y agoThat's a bold assumption, depending on your audience.
- vxNsr 8y agoBut as others have said either way email is an attack vector because it's often used for account recovery, this way at least it's a lot clearer who is in charge of security, it's the user and the email provider (whether they like it or not).
- thaumaturgy 8y agoIt is a lot inconvenient, given the various and myriad issues with guaranteeing email deliverability. Multiple hosting providers use greylisting or something like it which can delay email by minutes to hours, depending on the behavior of the sending mail server. Almost all hosting providers use one or more layers of spam filtration which can incorrectly trap or dispose of your message. Many users have additional mailbox rules set up which may accidentally match your message and route it to an unexpected folder. Relatively small mistakes with things like SPF can further complicate deliverability. You may also use some popular mail delivery service or another, which means that when that service has a bad customer that annoys enough other system administrators, the entire service gets blackballed, your messages along with it. (Hi, SendGrid.) DigitalOcean's two-factor authentication used email, and email only, which several times caused us some headaches when there was an urgent issue and our person-in-charge couldn't access the account. I've had a system administrator role for multiple companies over almost 15 years now. I've yet to see a perfectly reliable email system. Doing password resets over email is one thing (though I think SMS is still better). At that point, the individual no longer has access to their account anyway, and you're dealing with a much smaller number of impacted users. It's much worse to throw up your hands and say, "I don't want to deal with passwords, let's use email", especially now that there are so many good password-handling libraries for so many different development environments and numerous articles on proper password handling.
- hartator 8y agoOnly 90%?
- jhinra 8y agoI don't buy these numbers at all. 90% seems stupid high for retail. From the report, "[...] we rely on data from the Shape Network. Across the US, Shape’s customers represent: [..] 40% of Mobile Retail (by in-store payments)." "We estimated the number of credential stuffing attacks using the total number of credential stuffing attacks observed on Shape’s US customers and the total proportion of the US industry our customers represent." I'm really wracking my brain how they're measuring their marketshare of retail. Mobile retail as measured by in-store payments? Can someone explain that to me? Bottom line, this data comes from a company whose value proposition is that they sit between your company's servers and your clients and filters bad requests for you.
- ggggtez 8y agoWhy would you think 90% is high? That's only 9 in 10. Remember, attackers using dictionary attacks are going to be trying hundreds or thousands of log in attempts, and a real user is only going to try at most a handful of times. You don't need that many attackers to easily approach 99% or higher. I'd say 90% is likely conservative for some companies.
- jhinra 8y agoI think 90% is high for a few reasons: 1) Rate limiting of login attempts takes a bite out of the large numbers you're talking about. If we are only looking at retail companies without rate limiting, well, duh, I guess >90% makes sense, but I expect a large portion of the global e-commerce retail segment _does_ employ rate limiting of logins. 2) The report lists, "Averages derived from customers’ login traffic before Shape Enterprise Defense was deployed on login applications" - so this is absolutely a biased sample. These are clients that signed up for help stopping this problem. 3) It bugs me how ambiguous the report is about how they aggregate to 90%. I worry it's a simple [total fraudulent logins] / [total login attempts] across all their client retailers, which will be heavily biased by the retailers that don't have login limiting, and doesn't really describe the situation. A much better number I'd like is the median percentage of fraudulent logins attempts across retailers.
- 8y ago
- dahart 8y agoAny time I start an ssh server for myself on a publicly accessible IP, hackers account for roughly 100% of login attempts. The legit logins are in the noise, and dictionary attacks on username and password fill the logs. With decent passwords, it's not much concern, but nowadays, I disable password logins completely.
- greenshackle2 8y agoI see a ton of attempts on my server that has SSH on a non-standard port. I imagine they don't all run port scans and I'd see even more on port 22.
- LeifCarrotson 8y agoMy experience is the same. I set up a VPN for a coworker, who used it on 3 separate weeks away, connecting in total maybe 30 times. There were several MB of logs detailing illegitimate connection attempts. It makes me curious what's really going over the wires and airwaves we love to hate for their low capacity and high cost. How much of that traffic is junk?
- hellofunk 8y agoMy Macy’s account was hacked just this week. I got an email that my shipping address changed, and I logged in and saw several hundred dollars worth of pending items in the shopping cart.
- IdontRememberIt 8y agoOn our site, for an unknown reason almost 80% of the hacked accounts used are with @outlook, @hotmail, @live, etc domains. Does not look like they got the credentials from a massive leak. Issue with that, is that the hacker deletes our warning/advice emails. Not a funny situation to handle. Any idea about the source?