• Welcome to OGBoards 10.0, keep in mind that we will be making LOTS of changes to smooth out the experience here and make it as close as possible functionally to the old software, but feel free to drop suggestions or requests in the Tech Support subforum!

Hackers steal 1.2 billion passwords

TWDeac

Resident Astrophysicist
Staff member
Joined
Mar 9, 2011
Messages
22,079
Reaction score
889
Location
Cincinnati, OH
I'm getting annoyed with constantly changing so many passwords. Even with Lastpass it is still time consuming. I'm also left wondering about my defunct financial accounts. Those I no longer use or that have $0 balances. I guess I should be more careful about deleting bank account info and other sensitive information in those situations.

Give me a secure single sign on biometric solution please.
 
I'm getting annoyed with constantly changing so many passwords. Even with Lastpass it is still time consuming. I'm also left wondering about my defunct financial accounts. Those I no longer use or that have $0 balances. I guess I should be more careful about deleting bank account info and other sensitive information in those situations.

Give me a secure single sign on biometric solution please.

Biometric SSO with 2 step authentication, across every fucking system I touch. It's 2014 goddammit.
 
Biometric SSO with 2 step authentication, across every fucking system I touch. It's 2014 goddammit.

Seriously. I should have been able to stick my weiner in the machine and unlock all my secrets YEARS AGO. Instead I just get a rash.
 
I'm pretty surprised there's not a native iPhone app yet called iAuth or something that provides an API for authentication using the fingerprint scanner and a pin or knowledge check. Facebook and gmail both have open auth API's - I think Apple must be worried about how secure the fingerprint scanner really is.

I just want to go to a website, click a separate global login button, then have my phone require a pin and a fingerprint combo, then the website let's me in. The tech is there already, and any site that lets you login using Facebook credentials could piggy back such a solution with minor changes.


Hopefully opening the iOS8 fingerprint api will lead to something like that sooner rather than later. And anyone who isn't using 2 factor for gmail is an idiot.
 
I'm getting annoyed with constantly changing so many passwords. Even with Lastpass it is still time consuming. I'm also left wondering about my defunct financial accounts. Those I no longer use or that have $0 balances. I guess I should be more careful about deleting bank account info and other sensitive information in those situations.

Give me a secure single sign on biometric solution please.

I've always heard this is potentially more problematic. Unlike passwords, you can't change a biometric if it is stolen or replicated.
 
I've always heard this is potentially more problematic. Unlike passwords, you can't change a biometric if it is stolen or replicated.

Then let's do a million digit password with a biometric two factor authentication plus NSA encryption. They can see all my shit. At least they aren't stealing my money.
 
Disclaimer: my knowledge of this is exclusively from the Wired article from 2012.

http://www.wired.com/2012/11/ff-mat-honan-password-hacker/all/

What about biometrics? After watching lots of movies, many of us would like to think that a fingerprint reader or iris scanner could be what passwords used to be: a single-factor solution, an instant verification. But they both have two inherent problems. First, the infrastructure to support them doesn’t exist, a chicken-or-egg issue that almost always spells death for a new technology. Because fingerprint readers and iris scanners are expensive and buggy, no one uses them, and because no one uses them, they never become cheaper or better.

The second, bigger problem is also the Achilles’ heel of any one-factor system: A fingerprint or iris scan is a single piece of data, and single pieces of data will be stolen. Dirk Balfanz, a software engineer on Google’s security team, points out that passcodes and keys can be replaced, but biometrics are forever: “It’s hard for me to get a new finger if my print gets lifted off a glass,” he jokes. While iris scans look groovy in the movies, in the age of high-definition photography, using your face or your eye or even your fingerprint as a one-stop verification just means that anyone who can copy it can also get in.

Does that sound far-fetched? It’s not. Kevin Mitnick, the fabled social engineer who spent five years in prison for his hacking heroics, now runs his own security company, which gets paid to break into systems and then tell the owners how it was done. In one recent exploit, the client was using voice authentication. To get in, you had to recite a series of randomly generated numbers, and both the sequence and the speaker’s voice had to match. Mitnick called his client and recorded their conversation, tricking him into using the numbers zero through nine in conversation. He then split up the audio, played the numbers back in the right sequence, and—presto.
 
It gets real annoying when traveling internationally without a global plan.

Yeah, but you can mitigate it. If you bring your own laptop you can just mark it as a trusted device and it won't re-hit you for a code. Plus just about everywhere has pre-paid SIM cards these days. Even in freaking Cambodia I paid $10 for a week of data on my phone, and once you sign into your google/apple account you get texts via data for the 2 factor codes.

But sure, if you have no global plan, no sim, borrow a laptop/computer - it does suck.

Personally I find biometrics overrated. Something you have, something you know, something that proves the requester is legit - those are all more important in my mind then "something you are" because it's hard to determine, easy to fake (usually), and impossible to change. Maybe once Google figures out how to instantly test your DNA...
 
Is this related to the fraudulent $500 PayPal transfer from my checking account I discovered yesterday?

womp womp.


I didn't change things last time around :couch: but am going to this time. Goodbye, passwords I've learned so well.
 
How long until rj starts a thread asking for help in resetting his hotmail password
 
Back
Top