3 ms·
It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff. At this
by ve55 5y ago
It would certainly be a nice time to stop using SSNs as keys, SMS as 2FA, and more importantly having next to zero consequences for this kind of stuff.
At this point we just expect this to keep happening over and over again with nothing changing, it's a very strange thing to observe...
- christophilus 5y agoJust this week, I had to sign into a service for a very large transaction I'm privy to. My password? The last 4 of my social. It's unbelievable how dumb so many of our systems are.
- cge 5y agoI'm in Ireland at the moment, where the health system, and vaccination process, appears to use mother's maiden name as a de facto password. There is no option to change it. It is often asked in person, and so can't be used as a placeholder. For business reasons, my mother has her parents' last name, I have hers, and this fact is easily discovered online with a few minutes research...
- specktr 5y agoOn a similar note, I setup my utility account this week. It was suggested by the representative that I use the last 4 digits of my SSN as a pin for my account. Pretty disappointing how short sighted many companies are when it comes to security practices.
- smsm42 5y agoThat's because if somebody gets in, it's not their problem for having lax authorization, it's your problem for being "victim of identity theft" and all the burden of proving it wasn't you rests on you. It costs them nothing to give out horrible advice, so they do it.
- ttGpN5Nde3pK 5y ago+1. And orgs (gov and private) will continue to just ask for completely unnecessary information because, why not? Throw it in some database with root:root as the pw and shrug when it gets breached. It really needs to stop. The only person that loses is the person that now has to potentially deal with identity theft or getting doxxed for the rest of their life...
- 88840-8855 5y agoI guess that website admins dont really care as it is a sufficiently good measure to reduce spam/spam accounts/new registrations. Yes, I am a pessimist and I believe that. Why should website x care that there is a probability that the ISP is going to be hacked.
- codegeek 5y agoSMS as 2FA is so stupid. So many banks and financial institutions are doing it in America and it amazes me. I mean what are they spending million of dollars in compliance/security/SOC etc on if they can't get a basic 2FA done correctly ? And don't get me started on stupid password requirements where a more secure password generated in keypass etc won't be valid. Who builds this stuff today ?
- azinman2 5y agoIt provides good security for most people and is a big ease of use trade off. Hardware can be lost, software is difficult for most people to install and use. You need solutions that account for 95% of people. Ideally there’s non SMS for the other 5%, but unless Apple/Google/telcos come out with something better that’s built in, integrated, and dead simple, we’re stuck with SMS for a long time. Security is a spectrum.
- ikiris 5y agosms as 2fa raises the bar signifigantly for non organized attackers. You'd be amazed how much of the meth crowd that encompases.
- vlovich123 5y agoThe challenge I’ve found is that I end up with a lot of different MFA options which makes it hard to track where my exposure is. In some places I have two methods because I set up SMS when it was available and switched to an authenticator app and forgot to turn down SMS. It’s a shame there’s no SSO for personal accounts that established dominance so that I could just have 1 account I need to secure (although SSO solutions never put you in control of being able to minimize data leakage and let providers force you to disclose certain information for using their service).
- mulmen 5y agoCompliance is about liability, not security.