Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
bump_fn
Apr 12, 2004

two of them

cinci zoo sniper posted:

what the gently caress is wrong with your idiot island

a list of what isn't would be shorter

Adbot
ADBOT LOVES YOU

Bulgogi Hoagie
Jun 1, 2012

We
i haven’t had to do the verified by visa password character prompt for like two years now, it just skips the screen completely and verifies the transaction without any prompt these days, not sure if that’s better or worse lol

Main Paineframe
Oct 27, 2010

hobbesmaster posted:

they probably also think they might be held liable for an employee stealing poo poo but not a hacker

unless I'm missing something (besides a tremendous secfuck) bank employees shouldn't need any characters from a users password, ever

Chalks
Sep 30, 2009

Bulgogi Hoagie posted:

i haven’t had to do the verified by visa password character prompt for like two years now, it just skips the screen completely and verifies the transaction without any prompt these days, not sure if that’s better or worse lol

Yeah, same here - I assume it's some sort of cookie/browser fingerprint/geolocation "remember me" thing they've got going on. You'll still get it sometimes if you use a different browser or do it from a new location, but it's always "character x y and z" from your password rather than the whole thing.

cinci zoo sniper
Mar 15, 2013




Chalks posted:

Yeah, same here - I assume it's some sort of cookie/browser fingerprint/geolocation "remember me" thing they've got going on. You'll still get it sometimes if you use a different browser or do it from a new location, but it's always "character x y and z" from your password rather than the whole thing.

same, i rarely get multiple prompts on the same vendor

Wiggly Wayne DDS
Sep 11, 2010



Bulgogi Hoagie posted:

i haven’t had to do the verified by visa password character prompt for like two years now, it just skips the screen completely and verifies the transaction without any prompt these days, not sure if that’s better or worse lol
yeah they switched to it fingerprinting a while ago, which was fun as i was in the middle of looking for bypasses when they suddenly switched to that model without notifying anyone

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

Main Paineframe posted:

unless I'm missing something (besides a tremendous secfuck) bank employees shouldn't need any characters from a users password, ever

correctamundo

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



Chalks posted:

I get the same thing for the "verified by visa" security check password in the UK. Surely that's an international system though?

issuing banks must have some control over the flow because one of my visas always asks for a password (8 alphanumeric chars max lol) and the other never has

canis minor
May 4, 2011

Recently I've had a pleasure of gaining back access to my online bank account, because the number of the ID card I've had was different from what the bank had in the system (I've changed the ID card without notifying the bank, something that the bank didn't notify me that I need to do) and I didn't remember my bank ID number.

To get through it though, I've had to print out a document stating that I'm changing my information and send a scan of it to the bank (bank is in different country I'm at) - what I find weird though, is that I could have changed any of my information, while attaching a photo of my ID card (so, there's no verification if I'm me at this point; what if the image of my ID card has been photoshopped; what if somebody found my ID card - I simply didn't need to provide any information about the bank account at the point of changing that information). On the other hand - how would verify this, I don't know. The first thing I've asked, is do they send a "forgotten password" package to home address registered to the account, and they said no, so...

El Mero Mero
Oct 13, 2001

Looks like they changed it, but that reminds me of how the old National Student Loan Database login system used to look:

Bulgogi Hoagie
Jun 1, 2012

We

El Mero Mero posted:

Looks like they changed it, but that reminds me of how the old National Student Loan Database login system used to look:



what next, you have to do a caesar cipher puzzle to gain access to your account lol?

Chalks
Sep 30, 2009

Holy poo poo. I just got a text message saying that my WhatsApp subscription has expired and I should go to some web address to pay for a lifetime subscription.

Apparently it's a scam, but it came from the same "number" as the WhatsApp account verification text.

That's pretty hosed up.

Shame Boy
Mar 2, 2010

Chalks posted:

Holy poo poo. I just got a text message saying that my WhatsApp subscription has expired and I should go to some web address to pay for a lifetime subscription.

Apparently it's a scam, but it came from the same "number" as the WhatsApp account verification text.

That's pretty hosed up.

spoofing caller ID is trivial, me and my miscreant highschool buddies used to do it all the time

fun fact: if you set the caller id to the same number you're currently calling a lot of the times (at least back in the mid-2000's) the phone system will think you're the owner of the phone and you'll get their voicemail inbox, which back then at least tended to never actually have a pin set (or set to anything besides 1234)

power botton
Nov 2, 2011

Isnt that how the British phone hacking stuff went down.

wolrah
May 8, 2006
what?

ate all the Oreos posted:

spoofing caller ID is trivial, me and my miscreant highschool buddies used to do it all the time

fun fact: if you set the caller id to the same number you're currently calling a lot of the times (at least back in the mid-2000's) the phone system will think you're the owner of the phone and you'll get their voicemail inbox, which back then at least tended to never actually have a pin set (or set to anything besides 1234)
This still works in a surprising number of cases.

Way too many people seem to ignore or forget the fact that anyone with a PRI or a sufficiently open VoIP provider can spoof caller ID however they want. Caller ID is about as trustworthy as the "From" field on an email. It literally takes me three clicks to change my caller ID to whatever I want.

power botton posted:

Isnt that how the British phone hacking stuff went down.
Yup.

Shame Boy
Mar 2, 2010

wolrah posted:

This still works in a surprising number of cases.

Way too many people seem to ignore or forget the fact that anyone with a PRI or a sufficiently open VoIP provider can spoof caller ID however they want. Caller ID is about as trustworthy as the "From" field on an email. It literally takes me three clicks to change my caller ID to whatever I want.

Yup.

i think i mentioned it before but i've just recently started to get the occasional confused angry calls from strangers telling me that "i don't want what you're selling!" and "please take me off all your lists!!!" which i'm guessing means my number has made it into the list of spoofed numbers some telemarketer is using :sigh:

fins
May 31, 2011

Floss Finder
https://medium.com/@alex.birsan/messing-with-the-google-buganizer-system-for-15-600-in-bounties-58f86cc9f9a5

breaking into google's internal bug tracker.

akadajet
Sep 14, 2003

lol from the adobe leak
https://twitter.com/thegrugq/status/925038396182970368

Proteus Jones
Feb 28, 2013




AHAHAHAHAHAHAHA

Bunni-kat
May 25, 2010

Service Desk B-b-bunny...
How can-ca-caaaaan I
help-p-p-p you?

Chalks posted:

Holy poo poo. I just got a text message saying that my WhatsApp subscription has expired and I should go to some web address to pay for a lifetime subscription.

Apparently it's a scam, but it came from the same "number" as the WhatsApp account verification text.

That's pretty hosed up.

I got an email saying I had just renewed my PayPal subscription.

:wtc:

The_Franz
Aug 8, 2003

ate all the Oreos posted:

i think i mentioned it before but i've just recently started to get the occasional confused angry calls from strangers telling me that "i don't want what you're selling!" and "please take me off all your lists!!!" which i'm guessing means my number has made it into the list of spoofed numbers some telemarketer is using :sigh:

with voice providers offering anti-spam call filtering this will probably happen more and more since stealing legit numbers is probably a good way to avoid the system

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

The_Franz posted:

with voice providers offering anti-spam call filtering this will probably happen more and more since stealing legit numbers is probably a good way to avoid the system

oh yeah, it’s already happening

I get like one call a week from a number known by att to be spam

and two a day from my area code and exchange

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
the whole situation would be trivially solved with legislation. the phone companies already know who they're going to bill for a call, independent of the actual caller id

all you need to do is shuffle liability around to give them an actual incentive to solve it

Midjack
Dec 24, 2007



Proteus Jones posted:

AHAHAHAHAHAHAHA

30 TO 50 FERAL HOG
Mar 2, 2005



Jabor posted:

the whole situation would be trivially solved with legislation. the phone companies already know who they're going to bill for a call, independent of the actual caller id

all you need to do is shuffle liability around to give them an actual incentive to solve it

yeah the only time you get real 100% absolutely reliable caller ID is if you are an 800 number. because you are literally paying to receive the call

Shaggar
Apr 26, 2006
lol nope. where did you hear that?

Doom Mathematic
Sep 2, 2008

Volmarias posted:

I asked for another time pad but they told me no, you only get one.

So it's not just a clever name!

30 TO 50 FERAL HOG
Mar 2, 2005



Shaggar posted:

lol nope. where did you hear that?

800 numbers receive ANI data which is actually set by the originating telecom

just did some searching on it, and it looks like its not valid for VoIP calls and a few other situations (operator forwarded calls) but even then the originating caller isn't the one setting those values

Shaggar
Apr 26, 2006
the originating telecom will accept whatever is sent by the originating circuit. sometimes they will restrict outbound ANI to known numbers associated to the originating circuit or trunk group but not always because it doesn't make sense for every design.

hobbesmaster
Jan 28, 2008

can't you route it through "totally legit russian phone company" and get whatever ANI you want or something?

maskenfreiheit
Dec 30, 2004

hobbesmaster posted:

can't you route it through "totally legit russian phone company" and get whatever ANI you want or something?

El Mero Mero
Oct 13, 2001

Proteus Jones posted:

AHAHAHAHAHAHAHA

PIZZA.BAT
Nov 12, 2016


:cheers:



:grin:

Raere
Dec 13, 2007

it has upper, lower, and a number. not bad for a password set by an old person

akadajet
Sep 14, 2003

Raere posted:

it has upper, lower, and a number. not bad for a password set by an old person

Yeah, but it's one of the most commonly used passwords. So...

Qwijib0
Apr 10, 2007

Who needs on-field skills when you can dance like this?

Fun Shoe

akadajet posted:

Yeah, but it's one of the most commonly used passwords. So...

doesn't look like love, sex, secret, or god to me.

Optimus_Rhyme
Apr 15, 2007

are you that mainframe hacker guy?

Qwijib0 posted:

doesn't look like love, sex, secret, or god to me.

EndlessRagdoll
May 20, 2016

Qwijib0 posted:

doesn't look like love, sex, secret, or god to me.

monkey123

PIZZA.BAT
Nov 12, 2016


:cheers:


Qwijib0 posted:

doesn't look like love, sex, secret, or god to me.

hunter1

Adbot
ADBOT LOVES YOU

Bulgogi Hoagie
Jun 1, 2012

We
https://twitter.com/iblametom/status/925398887061483520

  • Locked thread