20 ms·
https://login.swissid.ch https://login.swissid.ch does this too: disallow password managers from filling out the login. Upon asking them to fix: "Autofill compl
by nickray 8y ago
https://login.swissid.ch https://login.swissid.ch does this too: disallow password managers from filling out the login. Upon asking them to fix: "Autofill completion is not allowed by us for security reasons. First, if that's the case, if someone gets to your PC, we can stop a hacking attempt and that's one of many reasons. For other questions, we are at your disposal."
They also only enforce SMS as two-factor authentication.
The idea of this SwissID is to become a nation-wide identity service, yet they manage to do everything wrong. Yeah, this annoys me to no end :(
- sschueller 8y agoMe too as we already had an attempt called suisse ID (10 years ago now?) and mobile ID. Both which cost money limiting adaption greatly. Personaly I like mobile Id which makes logging into PostFinance or swisscom easy but not all phone providers are able to offer it. Sucks that for post and sbb I need yet another system, Swiss id....
- ThePadawan 8y agoNotably, SwissPass did not allow me to set a randomly generated, very long (>20 character) password. It also didn't notify me that it didn't allow such passwords, it just went right ahead and created an account it was impossible to log in to. Thankfully, I was able to reset the password to one which is far unsafer. Well done everyone.
- davchana 8y agoIndia Government's official Website for managing public retirement fund, NPS, eNPS does this. Password need to be changed every 90 days, of max 14 characters length, but no where documented. On password change page, it will silently accept your any 14+ length password & will truncate it to 14. Then you try to login with your actual password, it gives error, Wrong Password.
- FabHK 8y agoThat's just stunningly bad (both the 90 days reset, and the silent (!) truncation to 14 characters...)
- mikestew 8y agoIn the U. S., Washington state's initial rollout of their ACA site did that. Gave it a big, long >20 char password, it created the account, go to log in and... How did I figure out what was going on? They would happily email your password in plain text. </facepalm>
- r3bl 8y agoThe first thing I would try in that situation is to input the first 16 characters of that randomly generated password. I've stumbled upon login fields that just dismissed everything after the 16th character a few times.
- cstuder 8y agoI too have a bad feeling about SwissID. Only SMS as two-factor authentication, turned off by default. No other methods planned, according to the support. The fact that the Swiss Post requires it as login method makes me uneasy.
- dcbadacd 8y agoCan someone explain what security does forbidding pasting provide? My brain just can't comprehend it. Also, would a fix be a password manager that just ignores the forbidding or is it done with JS somehow?
- zaarn 8y agoForbidding pasting provides the security of having to click "Inspect elements" before the hacker can proceed. (Most PW manager plugins I know already ignore pasting properties, though a bank I was customer of circumvented that; the textbox was actually a DIV and they had coded the functionality of a textbox into it to prevent pasting)
- asdkhadsj 8y agoYea, I ran into a bank that did that too. Then they proceeded to ask me a half dozen "security" questions from a massive list I could choose. Most of which I didn't know the answer to. I answered all of them (and put my answers down in my pw manager) with something like "X bank has terrible security, I hate this bank" - hoping that one day I'll have to answer those by phone haha.
- ceejayoz 8y agoI thought I'd seen it all until I had to set my United Airlines security questions. Not only are the questions picked from a list, but the answers are. http://www.slate.com/articles/technology/future_tense/2016/03/united_airlines_uses_multiple_choice_security_questions.html http://www.slate.com/articles/technology/future_tense/2016/0...
- tvanantwerp 8y agoI always answer the security questions with gibberish that I also save with my password manager. I now use a method like correct-horse-battery-staple to create answers, but I used to use long alphanumeric strings. I switched methods because, yes, one day I had to read the answer over the phone. Rep: "Tell me the answer to this question." Me: "Ok, let me see what I set it to..." Answer: F^O9dA66@wUPpK5$lTXBbrQ#yLP1EGl$ Me: "Oh... Oh no."
- Aeolun 8y agoWhenever I see messages of this kind, there is some doubt light that turns on in my head. Wondering if it’s possible I missed something, but I always have to conclude that, no, there isn’t anything wrong with my thought process. They really are just that clueless...
- timvdalen 8y agoHah, that page actually allows you to test whether or not a certain email address is signed up for the service, which seems like an even worse idea given what they're to become.
- kazagistar 8y agoHow do you actually prevent this? It seems impossible to prevent that information from leaking via timing attack.
- dasil003 8y agoRequiring a timing attack and having throttling on any such endpoints raises the bar quite a bit by itself. As to preventing timing attacks you can add a delay to give a uniform response time.
- CiPHPerCoder 8y ago> As to preventing timing attacks you can add a delay to give a uniform response time. You have to be very careful with how you implement the delay to prevent the timing signal from still propagating to the attacker. https://blog.ircmaxell.com/2014/11/its-all-about-time.html#A-Note-On-%E2%80%9CRandom-Delays%E2%80%9D https://blog.ircmaxell.com/2014/11/its-all-about-time.html#A...
- jedberg 8y agoUsually you do it by giving the same response for an invalid password and a non-existent email. I wanted to see how that particular page was leaking but the site wouldn’t load for me.
- RcouF1uZ4gsC 8y agoThat won’t really help in general because you can go try to sign up with an email address. It has to tell you if the address is already taken or not.
- auslander 8y agoSafari does it best. I does not fills the box, until you click on it, then it gives you the choosing list to click an entry. That prevents the page's JavaScript code to read autofills before user action. Regarding can you trust Troy, check this out https://news.ycombinator.com/item?id=17398821 https://news.ycombinator.com/item?id=17398821