Comment by zkmon
4 days ago
> My banking app requires, on average, three FaceID logins before the 3D Secure confirmation view appears.
That's a different, equally big problem. Security mafia at every company will continue to rule everything and everyone. They do not have goals or constraints that are tied to productivity and user experience.
We are heading to a situation where the security teams are causing much more damage compared to the possible attack vectors. While this damage is real and certain, the damage due to attack vectors is only hypothetical.
Ofcourse, we do need security. But currently no one including CEO can dare to define how much security is needed. On top of that, regulators do their own share of damage, piling up regulations. No one takes any risk. They will ask you to tie yourself down until you can't move. Your mobility is not their problem.
Perhaps its a slight overcorrection but it's better than the past where an online shop I gave my credit card info to would reply to a forgotten password request with an e-mail with my password in it in plaintext. Security used to be awful and people suffered because of it.
I wonder how many accounts have ever actually been compromised by a MITM reading passwords out of plaintext emails. I would guess it's very, very small.
I believe the bigger failure mode in that scenario is the fact that the site was storing user passwords in plaintext (either directly or effectively). Users tend to reuse passwords, so when there's a breach, more than just the user accounts for that site would be compromised.
No site should be able to give you your password because they should never store it. They store the hash of the password and whatever password you provide is then hashed and compared to the stored hash.
That way, when their security is compromised, the attacker doesn't get your password.
Any site giving you your password is doing it wrong because they should never know it.
NSA probably read and stored a highly significant fraction of those emails.
This is a very odd take in the world where your device will connect to any old wi-fi.
On top of that any takeover of a device like an ISP router or BGP misrouting is now an automatic compromise.
One thing you can do to fight back is show up at their branches with complaints. You can engineer this intentionally. Have a bank that doesn't support Graphene? Show up with your Graphene phone and be like "it says my phone isn't allowed. Fix this or I'm closing my account" and there's a 50% chance they will turn off phone hardware attestation for your account or give you a physical 2FA token and if they don't it will show up in their metrics.
That’s a hilarious comment in the world where companies are getting hacked left and right and consumer data is widely available from how many pieces of software have piss poor security. You might work at companies as where dumb bureaucrats have a tight grip on things, but in most of the world, security practices are not holding us back, they simply don’t exist.
The the op of this thread is really security clueless. The moment you're in most networks you can move laterally and get whatever you want. Locking these systems down and securing them is very difficult work. After C levels, developers are the worst at security in companies.
Drum it out loud.
Some organizations are stuck in proverbial cobwebs of security blankets.
Those who dictate what security should be have no skin in the game, the end result is just stupid.
My pet hate when I still worked was "defence in depth". I witnessed this term being thrown around to the point it was only an excuse.
A lot of box ticking paper pushers in the space, somehow making the scene a clown show.