Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • Remote
  • Global
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • Remote
  • Global
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Sketchy)
  • No Skin
Collapse
Wandering Adventure Party Logo
  1. Home
  2. General Discussion
  3. I’m gonna need everyone in security to internalize this.

I’m gonna need everyone in security to internalize this.

Scheduled Pinned Locked Moved General Discussion
1 Cross-posts 38 Posts 22 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • TindraT Tindra

    I’m gonna need everyone in security to internalize this.

    Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

    Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

    If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

    AndreD This user is from outside of this forum
    AndreD This user is from outside of this forum
    Andre
    wrote on last edited by
    #21

    @TindrasGrove while I support 2FA, passkeys, etc for security reasons, this goes to show that smartphones and certain essential softwares should be accessible and affordable/free to all.

    We made everything more accessible through digitalization, but handed the key to the gate to a select few corporations, hiking prices and excluding those that just want to participate, but lack the will or funds to do so.

    AndreD 1 Reply Last reply
    0
    • AndreD Andre

      @TindrasGrove while I support 2FA, passkeys, etc for security reasons, this goes to show that smartphones and certain essential softwares should be accessible and affordable/free to all.

      We made everything more accessible through digitalization, but handed the key to the gate to a select few corporations, hiking prices and excluding those that just want to participate, but lack the will or funds to do so.

      AndreD This user is from outside of this forum
      AndreD This user is from outside of this forum
      Andre
      wrote on last edited by
      #22

      @TindrasGrove I should add: lack the will or funds to acquire the necessary tools. Especially for elderly folk it should only take the will to adopt the new tech and learn the use of it - it shouldn’t come with a pricetag of several hundred dollars & monthly subscription.

      1 Reply Last reply
      0
      • Fluffy Kitty CatF This user is from outside of this forum
        Fluffy Kitty CatF This user is from outside of this forum
        Fluffy Kitty Cat
        wrote on last edited by
        #23

        @darkcat09 @TindrasGrove an attacker may well only have an email and a password from a leak somewhere and is trying to see if they can score a breakin from a password reuse

        1 Reply Last reply
        0
        • Jernej Simončič �J This user is from outside of this forum
          Jernej Simončič �J This user is from outside of this forum
          Jernej Simončič �
          wrote on last edited by
          #24

          @mirabilos @ajn142 Your password manager should detect that you're on the wrong site, and shouldn't offer auto-fill at all.

          1 Reply Last reply
          0
          • Jernej Simončič �J This user is from outside of this forum
            Jernej Simončič �J This user is from outside of this forum
            Jernej Simončič �
            wrote on last edited by
            #25

            @darkcat09 @TindrasGrove Sure it does, SMS slightly more than e-mail (as it's a different channel entirely) – both will prevent password spray attacks, which is good enough for 90% of people.

            They won't stop targeted attacks, but those aren't a concern for majority of people.

            1 Reply Last reply
            0
            • TindraT Tindra

              I’m gonna need everyone in security to internalize this.

              Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

              Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

              If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

              Trillian ✅✝️ 🇬🇧👍O This user is from outside of this forum
              Trillian ✅✝️ 🇬🇧👍O This user is from outside of this forum
              Trillian ✅✝️ 🇬🇧👍
              wrote on last edited by
              #26

              @TindrasGrove Also, in the UK landline phones are being switched off. They can only be used via a broadband router.

              John PettigrewJ 1 Reply Last reply
              0
              • Trillian ✅✝️ 🇬🇧👍O Trillian ✅✝️ 🇬🇧👍

                @TindrasGrove Also, in the UK landline phones are being switched off. They can only be used via a broadband router.

                John PettigrewJ This user is from outside of this forum
                John PettigrewJ This user is from outside of this forum
                John Pettigrew
                wrote on last edited by
                #27

                @oldrawgabbit @TindrasGrove Although, hilariously, my landline was supposed to be turned off this week and turned into a VoIP service. But *on the day*, I got an email from VirginMedia saying "Oopsie, we're delaying this indefinitely. Just store the adaptor we sent you in a drawer somewhere." How badly do you have to have messed up the planning on a migration like this to have to cancel at the last minute? 😱

                1 Reply Last reply
                0
                • Daniel LeighD Daniel Leigh

                  @tknarr @TindrasGrove SMS, email, and other "less secure" 2fa methods are far from useless. They prevent untargeted attacks. If your threat profile includes a persistent attacker going after you specifically, sure they are insufficient, but that isn't a reasonable threat profile for a vast majority of accounts on any service.

                  Todd KnarrT This user is from outside of this forum
                  Todd KnarrT This user is from outside of this forum
                  Todd Knarr
                  wrote on last edited by
                  #28

                  @danielleigh @TindrasGrove No, they don't protect from untargeted attacks. Someone scanning eg. Paypal logins looking for vulnerable ones will have the phone number associated with it. They don't have to be targeting a specific person to look up the carrier info for that phone number and clone the SIM. Email is a little harder if you use a client, but webmail is vulnerable to standard browser compromises.

                  1 Reply Last reply
                  0
                  • TindraT Tindra

                    I’m gonna need everyone in security to internalize this.

                    Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                    Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                    If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                    gioS This user is from outside of this forum
                    gioS This user is from outside of this forum
                    gio
                    wrote on last edited by
                    #29

                    @TindrasGrove I’ve been working in this space for 20+ years. I agree more of us need to see cases like this. They are not corner cases. They are significant numbers of people in large populations and have to be considered when we design authentication systems. Thanks for sharing this.

                    1 Reply Last reply
                    0
                    • F OddOpinions5

                      @TindrasGrove

                      I think about 95% of adults in wealthy countries have a smart phone

                      So about 95% have access to online registration ?

                      of th remaining 5% a lot are grouches like me, I don't have a smartphone but can obviously can use the internet

                      of the remaining what, 1% of adults who don't have a smartphone or a laptop, maybe 50% can access these things at a library ?

                      roughly ?

                      very few systems work smoothly for the last half percet

                      cubeQ This user is from outside of this forum
                      cubeQ This user is from outside of this forum
                      cube
                      wrote on last edited by
                      #30

                      @failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.

                      F 1 Reply Last reply
                      0
                      • AndreD This user is from outside of this forum
                        AndreD This user is from outside of this forum
                        Andre
                        wrote on last edited by
                        #31

                        @rickf @TindrasGrove I understand that & what I am saying is: this already challenging enough - they shouldn’t have to commit to costs to participate or use basic services on top of everything else.

                        But as digitalization progresses, access becomes essential and you are forced to pay for it.

                        I’m addressing a different angle to the topic as well, so to say. In no way am I invalidating the statement.

                        1 Reply Last reply
                        0
                        • cubeQ cube

                          @failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.

                          F This user is from outside of this forum
                          F This user is from outside of this forum
                          OddOpinions5
                          wrote on last edited by
                          #32

                          @qbe @TindrasGrove

                          absolutely
                          but as I tried , and possibly failed, to say, it is very hard to design systems that work well for the half percent

                          1 Reply Last reply
                          0
                          • AndreD This user is from outside of this forum
                            AndreD This user is from outside of this forum
                            Andre
                            wrote on last edited by
                            #33

                            @rickf @TindrasGrove sorry - I got a pretty hateful reply (which was deleted shortly after), so I felt a bit defensive.

                            1 Reply Last reply
                            0
                            • Epic NullE This user is from outside of this forum
                              Epic NullE This user is from outside of this forum
                              Epic Null
                              wrote on last edited by
                              #34

                              @alxndr @derAndereAndre @TindrasGrove My grandma would be a lot more secure if she simply did not need a smartphone. There is no version of the technology that would be appropriate for her as her mind ages.

                              Ideally her home would have a small computer lab for those few computer tasks, and she would spend more of her time offline.

                              What I am saying is "We need to stop pressuring everyone to have a fucking smartphone"

                              1 Reply Last reply
                              0
                              • Todd KnarrT Todd Knarr

                                @TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...

                                Epic NullE This user is from outside of this forum
                                Epic NullE This user is from outside of this forum
                                Epic Null
                                wrote on last edited by
                                #35

                                @tknarr @TindrasGrove But if we're talking about registration for an event that is probably at most three weeks away...

                                Why not use a 2fa that can be breached within months? The event will be over by then anyway, so you can just close down that account.

                                1 Reply Last reply
                                0
                                • Epic NullE This user is from outside of this forum
                                  Epic NullE This user is from outside of this forum
                                  Epic Null
                                  wrote on last edited by
                                  #36

                                  @patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.

                                  Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.

                                  TindraT 1 Reply Last reply
                                  0
                                  • Epic NullE Epic Null

                                    @patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.

                                    Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.

                                    TindraT This user is from outside of this forum
                                    TindraT This user is from outside of this forum
                                    Tindra
                                    wrote on last edited by
                                    #37

                                    @Epic_Null @patrizia I am right there with you!

                                    For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.

                                    For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.

                                    Epic NullE 1 Reply Last reply
                                    0
                                    • TindraT Tindra

                                      @Epic_Null @patrizia I am right there with you!

                                      For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.

                                      For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.

                                      Epic NullE This user is from outside of this forum
                                      Epic NullE This user is from outside of this forum
                                      Epic Null
                                      wrote on last edited by
                                      #38

                                      @TindrasGrove @patrizia Yeah a LOT of tech I have a problem with is forcing tech for corporarions onto home users.

                                      This stuff has risks PERFECTLY managable with a functioning IT department, but disasterous for home users.

                                      Bitlocker is a perfect example of this.

                                      Security advocates model your threats challenge.

                                      1 Reply Last reply
                                      0
                                      • KichaeK Kichae crossposted this topicto General on
                                      • KichaeK Kichae moved this topic from World

                                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                      With your input, this post could be even better 💗

                                      Register Login
                                      Reply
                                      • Reply as topic
                                      Log in to reply
                                      • Oldest to Newest
                                      • Newest to Oldest
                                      • Most Votes


                                      • Login

                                      • Login or register to search.
                                      • First post
                                        Last post