3 ms·
That exchange is not realistic, it's easy to ID family or friends by how they conversate. At worst you can ask a challenge question. The prompt that a device ha
by thinkloop 8y ago
That exchange is not realistic, it's easy to ID family or friends by how they conversate. At worst you can ask a challenge question. The prompt that a device has changed is perfect to heighten senses for a quick ID. I disagree that physical contact is necessary as TFA (and industry lore) seem to recommend:
> You must now reestablish identity, and in almost all cases, this means meeting in person and comparing "safety numbers" with every last one of your contacts
Perhaps the alert could be a little more alerty and in red and read something along the lines of "Hey! Your buddy's safety code has changed, make sure they sound normal and aren't acting weird and creepy asking for information"
- dabernathy89 8y agoHow many people are realistically going to pester their friends & relatives with "challenge questions"? I bet even the majority of folks in the HN crowd don't/wouldn't.
- thinkloop 8y agoI'm not saying you have to know their first pet's name. I'm saying it's usually pretty obvious through regular conversation if someone is who they say they are, and worst case, if you're suspicious, you can ask about some shared past event without them knowing that they're being challenged.
- dabernathy89 8y agoI could see some people doing this if they notice obviously suspicious behavior on top of the safety number change, but I suppose that depends on the skill of the attacker.
- skybrian 8y agoYou are basically saying that social engineering never works, but there are many stories about how social engineering sometimes works.
- feanaro 8y agoWhy does it have to never work? No technique is perfect.
- geofft 8y ago"I'd love to chat, but I'm lost in a foreign country. Can you just Venmo me some money so I can get home and then we can talk about $shared_past_event later?"
- deleted 8y ago[deleted]
- OJFord 8y agoI was impressed that my non-technical parents challenged my brother when he (or someone claiming to be him) (claimed to have) lost his phone and other possessions travelling. I think as long as the meta message about the change of key is prominent/scary enough, even non-HNers will be as on edge as necessary.
- allannienhuis 8y agoThis is exactly the weakness that phishing exploits all the time - they only need to succeed a small percentage of the time. If they rely on users being vigilant or noticing odd behaviour, they are guaranteed to succeed some percentage of the time. That's a flawed system, not something you should blame on the user.
- dchest 8y agoAt worst you can ask a challenge question You can NOT verify anything by asking a challenge question. Man-in-the-middle attack means there's a "man in the middle". That is, the attacker can relay challenge question and answer between the contacts it attacks.
- tialaramex 8y agoThe _protocol_ can be arranged to help you do this, but yes just asking a challenge question inline doesn't protect against a MITM. If Alice and Bob know a good secret (say a 128-bit AES key) then they can definitely just use that secret to protect their communications against the MITM. This only requires updating the protocol to allow such a secret to be introduced. Mallory can continue to relay messages, but they are now passive and don't learn anything beyond traffic analysis or have any ability to tamper with the messages. But chances are Alice and Bob don't have such a secret (and of course they can't use the potentially MITM'd channel to agree one) I _think_ if Alice and Bob know a weak human secret they can do something here with a Balanced PAKE. A PAKE lets two parties agree a key based on knowing some relatively weak secret, Mallory can try to guess but only gets one chance each time this is done and failure is detectable by Alice and/or Bob. Again this requires support in the chat protocol itself.