5 ms·
It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the indust
by da_n 13y ago
It amazes me that this type of social hack still works so successfully, I can understand Kevin Mitnick's success back when he was a hacker but surely the industry should have learnt by now. Resetting a users credentials should be treated like changing all the locks on their houses. If the user cannot verify their account credentials and is crying over the phone at least implement a 7 day delay and grace period before the reset takes effect, send emails which notifies the current email etc, or even send a pin to their postal address. I know these are not ideal security either but at least there would be some grace period.
- vitalysh 13y agoOr they could at least call back to the phone number stored on file.
- sp332 13y agoPhone companies really have learned from Mitnick. For example, if you call an operator, they absolutely will not tell you what number you called from.
- broolstoryco 13y agoHow would that be exploitable?
- sp332 13y agoIf you're exploring the phone system and want to know what circuit you've happened to sneak your way onto. It's very useful if you can have the phone company just tell you what part of their systems you're calling from :)
- lhgaghl 13y agoIf they're relying on such information for security, they aren't secure in the first place.
- pyre 13y agoI think that the idea is to not help out a potential attacker rather than to use this as an absolute security method. I think that we can agree that relying on any single security method is foolish. Maybe we shouldn't jump to conclusions that this is their only security measure in place.
- lhgaghl 13y agoIf they're relying on multiple weak pieces of information like this for security, they still aren't secure, and now they just created a huge pain in the ass for any user of their system, as they have to somehow know all the pieces of information which are supposed to be secret. Huge-pain-in-the-ass security doesn't tend to work very well...
- danielweber 13y agoThey don't have to be "relying" on it to use it. If you treat security like a mathematical problem [1] with no grey areas, you are going to reject almost every security measure and say "that would only give users a false sense of security." Just about all security measures can be worked around by a determined attacker. That doesn't mean you stop using them. The linked page says to hide your whois information. This is surely security through obscurity. Yet it can vastly reduce the number of reset emails you get. [1] You should treat crypto like a mathematical problem.
- oh_sigh 13y agoAlso known as "defense in depth" in the security field.
- Dylan16807 13y agoTo be picky, if you're treating it mathematically the phrase "sense of security" has no meaning.
- lisper 13y agoWhy would it not suffice to call yourself on your own cell phone and look at the caller id?
- deleted 13y ago[deleted]
- imroot 13y agoThat's not completely true. If you're in an old Ameritech area in Ohio, pick up the phone, dial '0' and when the Operator comes on, say: "OBT-125, please read number on display." You'll get the NPA-NXX-XXXX read out to you and she'll tell you to have a good day. As of three years ago, you could call any of the embarq/sprint area operators in Ohio/Kentucky and just say, "ID Me." Phone phreaking is still alive, but, it's not as common as it once was.
- ehPReth 13y agoWhat does 'OBT-125' signify/mean?
- sbierwagen 13y agoI'm guessing OBT is Ohio Bell Telecom, don't know about 125.
- imroot 13y agoOBT stands for Ohio Bell Telephone, and "125" is the job/billing code for a line splicing/Frame/Switch person.
- herokusaki 13y agoCan someone from the area try this and report back?
- ehPReth 13y agoOne could always call one of these instead: https://en.wikipedia.org/wiki/Automatic_number_announcement_circuit https://en.wikipedia.org/wiki/Automatic_number_announcement_...