Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
spankmeister
Jun 15, 2008






Before I used a password manager my system was to use a random password for pretty much everything except email and resetting every time I needed to log in.

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




spankmeister posted:

Before I used a password manager my system was to use a random password for pretty much everything except email and resetting every time I needed to log in.
please tell me you didn't have to regularly log onto more than a couple websites :gonk:

Chalks
Sep 30, 2009

What are people's thoughts on simply using browser password storage + a master password? That's presumably the same as using an external dedicated password manager since the password database is encrypted.

cinci zoo sniper
Mar 15, 2013




Chalks posted:

What are people's thoughts on simply using browser password storage + a master password? That's presumably the same as using an external dedicated password manager since the password database is encrypted.
no one knows (or knew as of last year) what and how they actually are doing (say, look up last year's opera breach), and passwords are not limited to websites only

spankmeister
Jun 15, 2008






cinci zoo sniper posted:

please tell me you didn't have to regularly log onto more than a couple websites :gonk:

It was mostly fine because a lot of sites were cookied. Or things like skype and steam or w/e that you only log in once per device usually. For stuff that I had to log in more frequently (bank, government etc) I just remembered the password.

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Chalks posted:

What are people's thoughts on simply using browser password storage + a master password? That's presumably the same as using an external dedicated password manager since the password database is encrypted.

i just let my browser remember my passwords since i think the realistic threat model is more "some skiddie breaks radium's code and gets my password" and less "ve haf vays of makink you talk, mr. bond"

Chalks
Sep 30, 2009

Wheany posted:

i just let my browser remember my passwords since i think the realistic threat model is more "some skiddie breaks radium's code and gets my password" and less "ve haf vays of makink you talk, mr. bond"

Yeah, I do the same - with 2fa for anything I give a poo poo about.

flakeloaf
Feb 26, 2003

Still better than android clock

i just like having passwords follow me from one computer to the next, because when you're using 4 different machines plus a phone, eventually they're gonna disagree on which browser has the right set of passwords and that's annoying

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

anyone use the Firefox sync feature? supposedly it works the same as a good password manager, where mozilla can't look at your data, but i never investigated it fully :effort:

cinci zoo sniper
Mar 15, 2013




Lutha Mahtin posted:

anyone use the Firefox sync feature? supposedly it works the same as a good password manager, where mozilla can't look at your data, but i never investigated it fully :effort:
i use, but only for cross-device bookmarks

bump_fn
Apr 12, 2004

two of them
hey sec thread how easy would it be to make a USB "charging" station that compromises every device that gets plugged into it because this is what I assume every USB port charging station is

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

bump_fn posted:

hey sec thread how easy would it be to make a USB "charging" station that compromises every device that gets plugged into it because this is what I assume every USB port charging station is

i think the difficulty level would depend a lot on how long you wanted it to be effective. if it was something you set up at a big event with lots of people walking around, where it's only active for a few hours/days, that wouldn't be super hard. but if you wanted it to be active long-term, you'd need some way to keep it updated with new vulnerabilities

Midjack
Dec 24, 2007



bump_fn posted:

hey sec thread how easy would it be to make a USB "charging" station that compromises every device that gets plugged into it because this is what I assume every USB port charging station is

there's been one set up in the hall at defcon for the last few years

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

fishmech posted:

That's about making sure your users with the Worst Passwords have to change.

lol if you think this will somehow make them choose good passwords.

you have made someone change password to Password1 congrats.

last.fm stands out most in my mind for this since it's a service i use a throwaway dont care password for. idgaf if someone manages to steal my scrobblin creds, surreptitiously auth to my account, and fill my listening history with hours of bieber.

if someone does bother to do that id be more amused than anything.

Pikavangelist
Nov 9, 2016

There is no God but Arceus
And Pikachu is His prophet



anatoliy pltkrvkay posted:

last.fm stands out most in my mind for this since it's a service i use a throwaway dont care password for. idgaf if someone manages to steal my scrobblin creds, surreptitiously auth to my account, and fill my listening history with hours of bieber.

if someone does bother to do that id be more amused than anything.

"someone"

Dylan16807
May 12, 2010

Lutha Mahtin posted:

anyone use the Firefox sync feature? supposedly it works the same as a good password manager, where mozilla can't look at your data, but i never investigated it fully :effort:

I can tell you that it used to generate a random key that required an existing device to participate in authorizing a new device

but then they changed it to just use the password https://blog.mozilla.org/services/2014/04/30/firefox-syncs-new-security-model/

it's probably fine if you use a good password?


oh amazing, they have conflicting documentation up for both versions https://support.mozilla.org/t5/Sync-and-Save/How-do-I-add-a-device-to-Firefox-Sync/ta-p/21091 https://support.mozilla.org/t5/Sync-and-Save/How-do-I-set-up-Sync-on-my-computer/ta-p/21417

Truga
May 4, 2014
Lipstick Apathy
both versions still work - if you have a legacy account it still works, and you're not required to upgrade. not sure if you can still add new devices to it though

the new version is because people kept forgetting their master keys and there's no way for mozilla to recover people's password like that, so they just have a password now. people ruin everything

Shame Boy
Mar 2, 2010

cinci zoo sniper posted:

i used to be like that before reading this thread - cool poo poo password for important things, and a few disposables for the rest

now i just click once to keep rear end and it's cool, thanks thread

i used to do that too and my main disposable from back then was only 8 characters and is now in rockyou.txt and someone's been systematically compromising all my old accounts that i don't use anymore and sending all my contacts spam

thanks, stupid young me :argh:

hifi
Jul 25, 2012

Truga posted:

both versions still work - if you have a legacy account it still works, and you're not required to upgrade. not sure if you can still add new devices to it though

the new version is because people kept forgetting their master keys and there's no way for mozilla to recover people's password like that, so they just have a password now. people ruin everything

i've got a recovery key from back when i used firefox. it's like 25 characters long

Shame Boy
Mar 2, 2010

"hey remember that skype account you made like over a decade ago as gokufan69420? no? well good luck figuring out which one it is when you start getting "lol u got hacked" messages from your friends"

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
just make sure to always use a phone number you have access to when you set up something for account recovery

i have an old gmail account i've pretty much lost

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate all the Oreos posted:

"hey remember that skype account you made like over a decade ago as gokufan69420? no? well good luck figuring out which one it is when you start getting "lol u got hacked" messages from your friends"

That's actually exactly what happened to me recently. The account recovery steps involved listing what your last payment was and listing people on your contact list, for an account that I last touched a decade ago.

Unsurprisingly, I was unable to recover it.

fisting by many
Dec 25, 2009



OSI bean dip posted:

just make sure to always use a phone number you have access to when you set up something for account recovery

i have an old gmail account i've pretty much lost

i had written off an old gmail account that I left tied to a phone number I no longer had, but it turns out you can answer some questions about usage (how old is your account, how often did you send emails, name some addresses you emailed) and have support give you access

somehow I guessed right enough which on one hand was shocking (it was a 10+ year old account and mostly a throwaway for signing up for unimportant websites) but on the other hand google probably has some cache of evidence linking me to it :shrug:

big shtick energy
May 27, 2004


quote:

The Canada Revenue Agency took its online services down at 1 p.m. Friday afternoon, after discovering an issue during website maintenance on Thursday night.

In an update posted on the CRA website, the agency said, "Upon becoming aware of an Internet vulnerability that affects some computer servers used by websites worldwide, we took down our online services, including electronic filing, and are taking steps to ensure that all information and systems remain safe."

The CRA said it isn't aware of any personal information being affected but will continue to monitor the situation.

Speaking to CBC around 2:30 p.m. Saturday, CRA spokesperson Patrick Samson said he does not have information on when online services will be available again. He said the CRA is currently working as quickly as it can to resolve the issue.

guessing it was the struts vulnerability but who knows

Zero One
Dec 30, 2004

HAIL TO THE VICTORS!
I have a login for a top-5 global bank that allows me to process international funds transfers (on behalf of my clients) worth millions of dollars.

It has 2FA which is in the form of a little authenticator with a keypad they mailed to me. I log into their website and then it prompts me to enter an 8 number challenge code into the device. It then gives me an alpha-numeric response to type into the website. Then I have a personal password.

Over the past few months I've discovered the website re-uses challenge codes. And not just like the same one after 60 days... I will often get the same code several times a week. There appear to be a max of 10 codes or so. Then the authenticator will give the same response to the same challenge code. It isn't salted based on the time or date or anything.

This has resulted in me memorizing the codes (I login and out multiple times a day) so I don't need to use the authenticator anymore.

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Zero One posted:

I have a login for a top-5 global bank that allows me to process international funds transfers (on behalf of my clients) worth millions of dollars.

It has 2FA which is in the form of a little authenticator with a keypad they mailed to me. I log into their website and then it prompts me to enter an 8 number challenge code into the device. It then gives me an alpha-numeric response to type into the website. Then I have a personal password.

Over the past few months I've discovered the website re-uses challenge codes. And not just like the same one after 60 days... I will often get the same code several times a week. There appear to be a max of 10 codes or so. Then the authenticator will give the same response to the same challenge code. It isn't salted based on the time or date or anything.

This has resulted in me memorizing the codes (I login and out multiple times a day) so I don't need to use the authenticator anymore.

5

bobfather
Sep 20, 2001

I will analyze your nervous system for beer money
I'd bet HSBC? I recall them having a lovely mouse-based PIN entry system 8 years ago when I had one of their credit cards.

jre
Sep 2, 2011

To the cloud ?



Zero One posted:

I have a login for a top-5 global bank that allows me to process international funds transfers (on behalf of my clients) worth millions of dollars.

It has 2FA which is in the form of a little authenticator with a keypad they mailed to me. I log into their website and then it prompts me to enter an 8 number challenge code into the device. It then gives me an alpha-numeric response to type into the website. Then I have a personal password.

Over the past few months I've discovered the website re-uses challenge codes. And not just like the same one after 60 days... I will often get the same code several times a week. There appear to be a max of 10 codes or so. Then the authenticator will give the same response to the same challenge code. It isn't salted based on the time or date or anything.

This has resulted in me memorizing the codes (I login and out multiple times a day) so I don't need to use the authenticator anymore.

Depressing but not surprising

Zero One
Dec 30, 2004

HAIL TO THE VICTORS!

bobfather posted:

I'd bet HSBC? I recall them having a lovely mouse-based PIN entry system 8 years ago when I had one of their credit cards.

It's Citi.

Not sure why I felt the need to protect them (to be clear I don't work for them, they are just a vendor for us).

edit: This isn't their personal banking. This is their commercial finance side.

Zero One fucked around with this message at 16:44 on Mar 12, 2017

Midjack
Dec 24, 2007



Zero One posted:

It's lovely

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

Zero One posted:

It's Citi.

Not sure why I felt the need to protect them (to be clear I don't work for them, they are just a vendor for us).

i want to know how unique each authenticator is :allears:

power botton
Nov 2, 2011

citi was the one who let you bring up anyones account as long as you logged in a-ok so I'm not shocked they don't get it

fisting by many
Dec 25, 2009



DuckConference posted:

guessing it was the struts vulnerability but who knows

when heartbleed hit a week before the filing deadline they took down e-filing temporarily and then extended the tax deadline by a month, i guess they'll do the same if they don't have e-filing back promptly

the CRA is ok :shobon:

a witch
Jan 12, 2017

fisting by many posted:

when heartbleed hit a week before the filing deadline they took down e-filing temporarily and then extended the tax deadline by a month, i guess they'll do the same if they don't have e-filing back promptly

the CRA is ok :shobon:

yeah :)

I want to check my refund status though

Truga
May 4, 2014
Lipstick Apathy

Zero One posted:

There appear to be a max of 10 codes or so.

sounds like someone finally implemented 10 factor auth

vOv
Feb 8, 2014

https://twitter.com/eorden/status/823924775177322497

Doom Mathematic
Sep 2, 2008

I'm shocked, shocked, that Signal can't close the analog hole.

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

What if someone takes a picture of the screen with another camera?

yes yes I know, Android has FLAG_SECURE and on iOS you can require a screen touch to view content

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
Weird. I wonder when Signal allowed for screenshots because it used to block attempts.

Adbot
ADBOT LOVES YOU

goddamnedtwisto
Dec 31, 2004

If you ask me about the mole people in the London Underground, I WILL be forced to kill you
Fun Shoe

OSI bean dip posted:

Weird. I wonder when Signal allowed for screenshots because it used to block attempts.

willing to bet enough users were like "hey i can't screenshot this hilarious thing someone sent me to post it to twitter" that they decided to change it

  • Locked thread