5 ms·
I think the poster meant the prior meaning of the word 'crypto' -- cryptography, in which the CFO could sign and encrypt some message and then the message's aut
by sargun 3y ago
I think the poster meant the prior meaning of the word 'crypto' -- cryptography, in which the CFO could sign and encrypt some message and then the message's authenticity could be verified.
- YetAnotherNick 3y agoHow does crypto add anything that just verifying email ID/phone number doens't provide. If you solution is to whitelist some certificates or key, you can as easily or even easier whitelist email IDs/phone number.
- pastage 3y agoCryptography can and should be done on hardware tokens that should directly be reported as stolen. A video call with email/phone is easy to fake. I work with people who all have hardware crypto, you are right that we do not have the organizational knowledge to verify everything with crypto. Even if the tech is 60% there.
- YetAnotherNick 3y agoMost company only allows logging in email in work devices, which is as easy to report stolen. What other kind of verification are we talking about which standard email DKIM doesn't have.
- acdha 3y agoEmail means I got access to your device or something you’ve configured to be able to send email, which is probably a lot of servers unless you have an entire domain dedicated to financial messages everyone knows not to trust any other domains. A message signature means I got you to do something like tap a Yubikey and enter a PIN, touch a fingerprint sensor, etc. That can still be socially engineered, of course, but it can’t happen by accident and you could add some safeguards against routine by having a dedicated “major transactions” key used only for that purpose to add a physical speed bump. The problem is that “ignore my gmail, I list my phone” will defeat that training more often than we’d like, so you really need to have process safeguards which make it a requirement and management backing to say even the CEO will follow the lost device process rather than asking someone to bypass process, and that has to be so carefully enshrined that nobody questions whether their job is on the line if they tell the real CFO that they can’t bypass the process.
- YetAnotherNick 3y ago> Yubikey and enter a PIN, touch a fingerprint sensor, etc Laptops and mobiles have all the same sensors. Most big companies have organization wide password, fingerprint and auto screen turn off requirement. Obviously not all companies follows good security practices or doesn't give secure devices(with sensors and encryption), but if that is the case Yubikey isn't going to save them.
- ghaff 3y agoI expect that most work emails are accessed from personally-owned phones.
- sverhagen 3y agoBanks certainly don't trust email, that's why instead they make you use those "encrypted messages" portals (...from hell).
- macrolime 3y agoPhone numbers are trivial to spoof or steal and there is currently no way to protect against that.
- YetAnotherNick 3y agoCare to explain how can I spoof other's phone number. Also phone is as hard to steal as any device where key is stored. In fact, people will remember their phone is stolen much before than the usb key or laptop or anything else.
- p_l 3y agoIf you can get S7 link with Telco, in most cases it's trivial to spoof Caller ID signals, as those are essentially forwarded from originating network. Getting direct S7 link isn't as hard as it sounds, it's IIRC common thing if yo want to run VOIP provider. Your telco's NOC can at best track what "port of entry" the call came from but can't force the Caller ID go be truthful.
- xur17 3y agoI imagine it has changed, but 10-ish years ago I recall having a cheap VoIP account that just let me enter whatever phone number I wanted as the caller ID.
- p_l 3y agoIt's very much a "honor system". If VoIP provider doesn't do due diligence, the other networks can't really check the value, especially since number porting became norm
- MichaelZuo 3y agoFor the first few dozen times sure, but after the hundredth or so report of a scam call associated with a spoofed number, the VoIP provider should be blocked by the telco. That is if they were allowed to do so.
- computerfriend 3y agoThis is a current, not prior, meaning of the word.
- subtra3t 3y agoI think many people would expand the word crypto to cryptocurrency and not cryptography. We can argue on and on about which is the "correct" expansion but in my opinion a word's current meaning should be the most popular association people have of it.
- MeImCounting 3y agoOnly on HN do I see people saying crypto actually mean like bitcoin or whatever. The rest of the technical world still knows crypto as cryptography.
- subtra3t 3y agoOnly on HN do I find people who actually know what cryptography is. Almost all the people I know have never heard of it, but all of them have heard of bitcoin, and most have heard the word crypto being used with reference to cryptocurrencies. That's not to say that my experience somehow means more than yours or is more valid. But I personally think my experience is more representative of the average layperson. You're welcome to disagree.
- MeImCounting 3y agoSure the non technical world is (sadly) more familiar with Bitcoin. I specifically said the technical world. Most people I know are technical to some degree and almost all of them would assume cryptography when they hear the word "crypto".
- thwarted 3y agophone beeps with SMS message from CEO "Can you buy $1000 worth of egift cards and text me back with the redemption codes? Our jobs depend on this. I'm in a very important meeting, otherwise of so it myself, left my private key at office and can't sign this message right now." The human element remains the weakest link.