6 ms·
After this past year with all of its vulnerabilities, I feel so uncomfortable when I really consider it. I make online payments at least a few times a week usin
by canadev 12y ago
After this past year with all of its vulnerabilities, I feel so uncomfortable when I really consider it. I make online payments at least a few times a week using my credit card. I log into my web based email multiple times per day.
I feel so naked.
Has anyone who uses brew and other dev stuff tried running Mac OS as a user account? Does it work out well?
- dguido 12y agoWorks fine.
- andrewchambers 12y agoThe real question is why don't credit cards and bank transactions have two factor auth, or one time tokens. Someone shouldn't be able to steal money just by hacking one account or getting one number.
- radmuzom 12y agoThis probably depends on the regulation of the country. For example, in India, by LAW, all domestic online transactions go through two-factor authentication. For one of my cards, I need to enter a secondary password while for another I need to enter a pin texted to my mobile. The second option is a hassle though, especially when I am travelling abroad and my standard mobile number is not functional. For international transactions, this does not apply and the card details are enough for the transaction to go through. I guess there is no standard agreement between countries which Visa, MasterCard or Amex can implement (these are the only payment networks I use).
- kalleboo 12y ago3DSecure works internationally and can be used to implement 2FA or passwords. It's common in parts of Europe and Asia, but seems less so in the US. http://en.wikipedia.org/wiki/3-D_Secure http://en.wikipedia.org/wiki/3-D_Secure
- austinl 12y agoIt's possible that this will change in the near future with things like https://getfinal.com/ https://getfinal.com/. Their product video also happens to be one of my favorites made by Sandwich (http://sandwichvideo.com/ http://sandwichvideo.com/).
- kalleboo 12y agoSome do, my Swedish debit card does. It only works on stores that support 3DSecure though https://www.flickr.com/photos/kalleboo/2486214902 https://www.flickr.com/photos/kalleboo/2486214902 (looking at the date of my photo, this has been in place for 6 years now)
- ersii 12y agoIn Sweden, all cards that are issued are forced to use that "Verified by" Visa and Mastercard "SecureCode" program for two-factor authentication. Merchants can turn it off, but then they're liable for misuse - so plenty of places have it on by default. Some banks, require that you use the token generator you've gotten to log on and manage your bank account while most other use a seperate password for the Verified by Visa/Mastercard SecureCode thing.
- ohyesyodo 12y agoI generate a one-time card number for each online purchase. Only valid for a specific time and up to a specific account. Supporter by some banks. Pretty good solution in my opinion.
- olov 12y agoI don't know if it's really fair to call Verified by Visa two-factor authentication as your card number is just another string (that can be replicated). With Verified by Visa you go from one to two "passwords".
- ersii 12y agoIt adds a "something you know" (password, PIN/Password to your token generator) factor to the "something I have" (The card, with numbers on front and back) factor, so I would say it's fair to call it two-factor authentication.
- olov 12y agoI beg to disagree. The credit card is "something you know" just as much as "something you have", because when used on the web it is just a (copyable) 23 digit number. Whether you remember the number or look it up in your wallet is no different than whether you remember your password or store it on a post-it. Other things "you have" in popular 2FA solutions are quite different, for instance your mobile phone number identity (for SMS) or your Google Authenticator.
- Oculus 12y ago
- noinsight 12y agoedit: I'm talking about online banking and money transfers from there-> In Finland one bank (Nordea) uses one-time passwords so you get a pad with passwords in the mail (they automatically send new ones when you're about to run out) and you need to use them sequentially to log in, only the numeric "username" is static. Then when you try to transfer money you also need to input a challenge-response from the same pad. IIRC another bank (Danske Bank) allows you to set a static username and password but you must also enter a challenge-response from a permanent pad to log in and to initiate transfers as well. Can't speak about the others but they should be about the same. Americans apparently just use a static username and password which is pretty mind boggling.
- addandsubtract 12y agoIn Germany, you get a unique PIN code via SMS to authorize every transaction.
- stevekemp 12y agoMy wife is Finnish, and I've seen that pad of "words" used. In the UK we tend to have a static username and password then either a hardware device, or a "Enter characters 1, 3, 8 from your secret information". (Where the secret information is 8-10 characters long and you're requested to enter from random offsets each time.) I've used both systems, and entering three characters from the secret information is the least hassle, but not as reassuring as the hardware token.
- oevi 12y agoIn Germany most of the banks use ChipTAN [1] for online banking. With that scheme it's impossible to make any transaction without having physical access to the card. [1] http://en.wikipedia.org/wiki/Transaction_authentication_number#chipTAN_.2F_cardTAN http://en.wikipedia.org/wiki/Transaction_authentication_numb...
- tomp 12y agoI really hate that. It means that I have to carry another wallet-sized thing around with me just to buy stuff online. Thankfully, my bank uses a password-based authentication system, so I can carry everything I need in my mind.
- TillE 12y agoI prefer the good old paper sheet of TANs, which at least DKB still uses. I had that exact pictured chipTAN reader; the display failed after about a year, and it was incredible hassle to get a new one activated with the Berliner Volksbank. It wasn't very good at reading the flashing barcode either, usually took a few tries. It's a good idea, certainly, just a partly lousy implementation. Some banks will offer the option of sending you a TAN via SMS instead (so your phone is the "something you have"), but usually for a fee.
- atmosx 12y agoMy Debit Card (VISA) is issued by a Greek bank (Piraeus Bank) and has two-factor authentication, for both sending money and making online payments. When I make online payments, I get redirected to a page where I have to answer a question/answer I've set-up a priori. The two-factor authentication is optional. I enable it to feel more secure. I don't make too many online payments, but I do at least 5-6 times per month.
- mosselman 12y agoHere in the Netherlands we have 2 factor authentication on all bank payments and most credit-card payments. The two-factor here works with a token-generating device in which you have insert your card and PIN. The only exceptions are unsafe US payment portals that don't support the two-factor triggers properly, but that is just for CCs. I lived in the US for 6 months and was surprised to find that my American collegues found it less safe to use a bank card (with PIN) than a CC. Their arguments were that 'if someone gets your card AND PIN, they can do anything' as opposed to someone stealing JUST your CC and then he can do anything... Yes seems much safer.
- belandrew 12y agoAll of my US credit cards have a verification number that is required as well as the CC number for any online transaction. It's not that much different from a PIN. We also have zero liability for unauthorized CC charges. So even if someone were to do that, the bank would be on the hook, not the user. Banks rely on a lot of computer analysis to determine whether a charge should be allowed. It's much more of a pain to get money back into your bank account after it's been withdrawn. So although it's technically true that a bank card with PIN is more secure, to the end user, it's not any better.
- coldtea 12y ago>All of my US credit cards have a verification number that is required as well as the CC number for any online transaction. It's not that much different from a PIN. Not at all the token system the parent describes.
- gpvos 12y agoThis depends on the bank. Ex-PostBank ING clients get a TAN via SMS for every transaction (or a paper list of TANs if you really want it). Recently, they added that when you log in from a different machine/location than usual, you get a similar code via SMS (or from a different but similar paper list, I guess), called a PAC.
- rcarmo 12y agoYes. I've been recommending that for years, actually: http://the.taoofmac.com/space/HOWTO/Switch http://the.taoofmac.com/space/HOWTO/Switch
- oneeyedpigeon 12y agoGreat stuff. I'm just about to set a new Mac up, and I'll be following a lot of the advice there.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- tptacek 12y agoYes. Everyone at Matasano runs from a standard user account. It's not a big deal at all. Nor is it a concession to insecurity on OS X; it's been Matasano's policy for almost a decade, and they inherited it from earlier companies, because not doing all your work from an admin account just makes sense.