3 ms·
It's true that a lot of sites don't go to the trouble of implementing particularly secure login systems (it's a lot of work!). Sadly I think this includes many
by mkjones 14y ago
It's true that a lot of sites don't go to the trouble of implementing particularly secure login systems (it's a lot of work!). Sadly I think this includes many banks.
One way around this is using SSO with a site who does spend a lot of resources on making their login system secure. For example, using Facebook Connect is a great way to get all that security (plus all our fake account detection) and the added bonus of not having to store (and properly hash) passwords. If only RockYou, Gawker, Sony and others whose credential databases have been compromised had done something like that... Fortunately, we have an answer even to problems like that with 3rd parties: http://bucks.blogs.nytimes.com/2012/04/02/how-facebook-tries-to-protect-users-online-credentials/ http://bucks.blogs.nytimes.com/2012/04/02/how-facebook-tries.... I've spent multiple nights up late trying to crack hashed passwords on a big dump before attackers can, so we can help the victims who shared credentials between the compromised site and Facebook secure their accounts.
I'd love to raise awareness around the stuff we do to protect users. We've done blog posts and people have written articles, and users often see this stuff when e.g. they're traveling (ever been asked to identify photos of your friends?). What else do you think we could do?
Here are some example articles about what we do around login security - if you're interested, check out http://www.facebook.com/security http://www.facebook.com/security to see other related stuff.
https://www.facebook.com/note.php?note_id=10150172618258920 https://www.facebook.com/note.php?note_id=10150172618258920
https://blog.facebook.com/blog.php?post=389991097130 https://blog.facebook.com/blog.php?post=389991097130
https://www.facebook.com/note.php?note_id=425136200765 https://www.facebook.com/note.php?note_id=425136200765
- tjoff 14y agoFor example, using Facebook Connect is a great way to get all that security (plus all our fake account detection) and the added bonus of not having to store (and properly hash) passwords. With the downside of compromising your users integrity and open your users up to even more tracking as well as relying on a 3rd party for a system-critical component and force your users to sign up for a facebook account. Storing and properly hash passwords is not hard to do. While I appreciate the work you do, facebook connect (as well as most, if not all, similar solutions) just sickens me and any service that exclusively rely on it is just pathetic (for the reasons above). Todo: Create multiple fake facebook accounts for such services, can't believe I haven't done this already. If you would just care to acknowledge that there might be potential issues with the things you mention your posts wouldn't seem like pure PR-statements.
- mkjones 14y ago> With the downside of compromising your users integrity and open your users up to even more tracking as well as relying on a 3rd party for a system-critical component and force your users to sign up for a facebook account. Obviously using Connect means that there's a 3rd party with some data about your users. IMO that's worth the tradeoff, but if you feel differently, then don't bother with Connect (though I'm curious what concrete concerns you have, more specific than just "opening them up to even more tracking"). As far as reliability goes, I agree that minimizing external dependencies is a good idea. Again, this is a tradeoff - you're saying "I want to work on things that are specific to my app or site, not this boring login stuff that has already been solved." I suspect that in reality, our uptime is good enough that sites are more likely to notice issues from their own (or their hosting provider's) instability than from ours. But you're right - this does introduce the possibility of login being broken for your site if Facebook is broken. Hopefully the benefits Connect offers outweigh this risk, but again, you're fee to not use it. > Storing and properly hash passwords is not hard to do. Perhaps it's not that hard, but many still people fail to do it properly. And it's still not a silver bullet - even properly hashed passwords, when exposed from a compromised DB, can be reversed. Regardless, this is only a small part of the problem - dealing with stolen (e.g. phished) credentials is another, arguably more important, problem that's much more difficult. > Todo: Create multiple fake facebook accounts for such services, can't believe I haven't done this already. Please don't do that. We're pretty aggressive about proactively seeking out fake accounts and getting rid of them, and as a result I imagine this would end up being a pain in the ass for you. I'm curious what threat this mitigates?
- tjoff 14y agoObviously using Connect means that there's a 3rd party with some data about your users. IMO that's worth the tradeoff, but if you feel differently, then don't bother with Connect (though I'm curious what concrete concerns you have, more specific than just "opening them up to even more tracking"). As a user: My integrity. I don't want to link accounts on otherwise completely different services. You have no business in knowing what other services I use and I see no, absolutely no, advantages to being forced to use facebook connect. As an alternative? Sure! But exclusively? No. You fail to mention the advantages with using facebook connect so I would really hesitate to call it a tradeoff when you have nothing to gain... And as a user I'm not free not to use it... And facebook haven't exactly had a solid track uptime record, it has even deserved a poor reputation in that regard - sure it isn't that bad but thing with relying on external parties is that it can only get worse than handling it yourself. http://www.pcworld.com/article/193423/facebooks_sneaky_apps_and_privacy_issues.html http://www.pcworld.com/article/193423/facebooks_sneaky_apps_... Perhaps it's not that hard, but many still people fail to do it properly. And it's still not a silver bullet - even properly hashed passwords, when exposed from a compromised DB, can be reversed. Regardless, this is only a small part of the problem - dealing with stolen (e.g. phished) credentials is another, arguably more important, problem that's much more difficult. The problem isn't, and has never been, that it is hard. The issue at hand is incompetence in its purest form and nothing else. And such incompetence will bite you in the ass regardless. Sure, I'd prefer my password not leaking but just deriving your password from the domain name or something like that is simple enough to combat that. In any case that is a tradeoff that isn't hard to make. External dependencies is not only something a developer has to take into consideration, as a user you have to keep track of permissions, ever changing security settings - but for what? If I don't want to link my music usage to my facebook account what possible can I gain from using facebook connect? Seriously? Have you guys even considered that scenario? Of course you have, you just couldn't give a shit about your users privacy or concerns. Rather make an easy buck than creating a good platform, just don't pretend you try to do both. You can't seriously argue that having to deal with all that shit is easier than signing up for a new account for every service. Please don't do that. We're pretty aggressive about proactively seeking out fake accounts and getting rid of them, and as a result I imagine this would end up being a pain in the ass for you. I'm curious what threat this mitigates? Even spotify recommends you to create an empty account ;) There is nothing you can do to stop me and the huge relief for my ass would be to not being afraid of spamming my friends with my spotify usage, not having to even care how spotify/whatever uses my facebook account (and how facebook/services will handle this in the future, facebook has a terrible reputation of adding new options with questionable defaults). Is it so hard to grasp that these are valid concerns? Valid concerns that should never, in anyones wildest dreams, ever have existed. There is nothing of value you can offer me but there are countless ways you can annoy the shit out of me. Solution? Create dummy facebook accounts. It is the only solution to the problem that you have created - suit yourselves. I don't trust facebook and I don't trust anyone else having any form of access to my facebook account (also, I'm so old fashioned that I don't even run executables that I get in the mail of an unknown sender). Anyway, thanks for making the web a worse place! If you ever find yourself working for someone other than Zuckerberg, please note that integrity issues is part of security as well.