Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Pile Of Garbage
May 28, 2007



fins posted:

Uk gov kinda secfuck: When setting up for 2FA for filing tax returns to HMRC, the instructions tell you to open an app store and search for "authenticator app". No specific one, just any authenticator app; their dev docs specify that its an oauth 2 token that's required.
What would happen if you got to the top of the store with "authenticator app"...

that's pretty cooked. by comparison here in AU it's kinda the opposite: a few years ago they centralised several federal gov services (ATO, Centrelink, Medicare, etc.) into a single portal called myGov. then not long after they introduced MFA support with a dedicated TOTP app: https://play.google.com/store/apps/details?id=au.gov.dhs.centrelink.mygovauthenticator (it's the only one that works with the portal).

however the app has no recovery code mechanism which they stress repeatedly with warnings like "IF YOU LOSE YOUR PHONE YOU ARE hosed AND HAVE TO GO TO A PHYSICAL DHS (DEPT OF HUMAN SERVICES) OFFICE TO UNFUCK YOUR poo poo". if you want to switch phones you have to disable MFA on your myGov account and then re-enable it with the app on your new phone.

so yeah, more secure but quite aggressive (hopefully not so much that it scares people off from setting it up). i think they also do MFA via SMS but gently caress that.

edit: gently caress me this is like my third snipe within an hour

edit2: lmao just saw the reviews of the app on the play store, 2.2 outta 5

Pile Of Garbage fucked around with this message at 11:27 on Jan 23, 2020

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

fins posted:

Uk gov kinda secfuck: When setting up for 2FA for filing tax returns to HMRC, the instructions tell you to open an app store and search for "authenticator app". No specific one, just any authenticator app; their dev docs specify that its an oauth 2 token that's required.
What would happen if you got to the top of the store with "authenticator app"...

that's unfortunately stupidly common: "search for [very generic description]" rather than the actual name of the thing they want you to use

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

dregan posted:

santander tried that with me, but they never trained their voice recognition on northern irish accents

luckily i rarely have to phone them, but when i do it's five minutes of disappointing a computer first

lol like this but diff. accent

https://www.youtube.com/watch?v=MNuFcIRlwdc

Achmed Jones
Oct 16, 2004



dregan posted:

five minutes of disappointing a computer

do not have sex with computer

Shame Boy
Mar 2, 2010

dregan posted:

santander tried that with me, but they never trained their voice recognition on northern irish accents

luckily i rarely have to phone them, but when i do it's five minutes of disappointing a computer first

i'm now imagining o'brien yelling at the enterprise's computer over and over again and it's real good

distortion park
Apr 25, 2011


mystes posted:

Companies such as advertisers buy people's transaction data from credit card companies, although I don't know if delayed somewhat or includes exact amounts? If it's detailed enough it could be a lot easier to obtain from the companies that buy it rather than directly from the banks.

Edit: It seems like it's supposed to be anonymized somewhat but I think it's also been previously reported that companies like Facebook have access to individual-level transaction data? You probably wouldn't even need 100% of recent transactions to make this work. In fact, any way of obtaining information on one or two recent transactions to mix in with made up fraudulent transactions would be enough to make this convincing. (I'm not saying that this actually happened here, but it's potentially worrying if this data is floating around for this reason.)

I know this is an old post but:
- the data is individual transaction level, with exact amounts and time and the description as it appears on your cc statement (minus anything an "ml" model can determine is pii)
- the anonymisation sucks and in any case the transactions are correlated by account, so some number of individuals are easy to identify. Similarly you can work out what the bank even though they are meant to be undisclosed
- it includes debits so in some cases you can work out employer and salary as well as where they shop
- I'm not sure it's the cc companies selling it mostly, as far as I know it's apps and account integrations, although I heard a rumor that some the card providers were selling it so who knows
- somewhere between 1 and 10% of the us population are in these datasets, there are multiple providers and there's no way bits of the data haven't leaked multiple times

Pile Of Garbage
May 28, 2007



Chris Knight posted:

that's unfortunately stupidly common: "search for [very generic description]" rather than the actual name of the thing they want you to use

this is partly why push MFA is more secure than TOTP: less risk of installing/using the wrong app that fucks with your phone and/or gives a third-party access to the generated pins. the dumb middle-ground is garbo corps making their own provisioned TOTP apps that are approved server-side (Symantec VIP comes to mind).

distortion park
Apr 25, 2011


If you wanted to run a targeted cold open blackmail scheme the card transaction data would be 100% the easiest way to do it at medium scale.

Shame Boy
Mar 2, 2010

Pile Of Garbage posted:

this is partly why push MFA is more secure than TOTP: less risk of installing/using the wrong app that fucks with your phone and/or gives a third-party access to the generated pins. the dumb middle-ground is garbo corps making their own provisioned TOTP apps that are approved server-side (Symantec VIP comes to mind).

we could just have authenticator apps built in to the phone the same way the dialer is or w/e so nobody has to get a critical security thing from the app store at random

i mean then you'd wind up having to use the LG Totally Secure TOTP App or w/e if you don't buy an iphone or goog-favorite phone but that's kinda a lateral move I guess

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

pointsofdata posted:

If you wanted to run a targeted cold open blackmail scheme the card transaction data would be 100% the easiest way to do it at medium scale.

It's also trivial to phish people's actual banking/CC credentials over the phone by pretending to be from the bank's fraud department and reading some of their old transactions to them. I've had a relatively cautious client get hit like this.

distortion park
Apr 25, 2011


infernal machines posted:

It's also trivial to phish people's actual banking/CC credentials over the phone by pretending to be from the bank's fraud department and reading some of their old transactions to them. I've had a relatively cautious client get hit like this.

It's something which you assume is private but really isn't! At least lots of people know that their phones are tracking their location.

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


if I was bezos I'd be getting so, so, many dongs shipped to bin salman right now

haveblue
Aug 15, 2005



Toilet Rascal

Powerful Two-Hander posted:

if I was bezos I'd be getting so, so, many dongs shipped to bin salman right now

every barrel of oil we buy from saudi arabia shall be returned filled with lube

Pile Of Garbage
May 28, 2007



Powerful Two-Hander posted:

if I was bezos I'd be getting so, so, many dongs shipped to bin salman right now

Amazon® DongStrike™

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
rods from god

Shaggar
Apr 26, 2006

Shame Boy posted:

we could just have authenticator apps built in to the phone the same way the dialer is or w/e so nobody has to get a critical security thing from the app store at random

i mean then you'd wind up having to use the LG Totally Secure TOTP App or w/e if you don't buy an iphone or goog-favorite phone but that's kinda a lateral move I guess

Microsoft authenticator is the only auth app anyone should use

FlapYoJacks
Feb 12, 2009

Shaggar posted:

Microsoft authenticator is the only auth app anyone should use

Even better, Microsoft Authenticator is 100% compatible with the Google Authenticator.

The Fool
Oct 16, 2003


does the google authenticator support push notification auth? we use the ms one at work and I just use it as a otp generator for everything as well so I've never actually touched the google one

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
they do not.

pseudorandom name
May 6, 2007

microsoft authenticator backs up your tokens to icloud which misses the point of 2FA

The Fool
Oct 16, 2003


pseudorandom name posted:

microsoft authenticator backs up your tokens to icloud which misses the point of 2FA

well, I assume the backup db is encrypted, but it's still silly
on android it just backs up to a personal ms account

Proteus Jones
Feb 28, 2013



The Fool posted:

well, I assume the backup db is encrypted, but it's still silly
on android it just backs up to a personal ms account

So does the iOS version.

The Fool
Oct 16, 2003


The ios version backs up to icloud.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

pseudorandom name posted:

microsoft authenticator backs up your tokens to icloud which misses the point of 2FA

nah

totp’s big win is that the credential expires and isn’t shared between services (since each service generates their own secret)

Jenny Agutter
Mar 18, 2009

Shaggar posted:

Microsoft authenticator is the only auth app anyone should use

I use it but is there a reason it doesn't support qr codes?

The Fool
Oct 16, 2003


Jenny Agutter posted:

I use it but is there a reason it doesn't support qr codes?

But it does

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

nah

totp’s big win is that the credential expires and isn’t shared between services (since each service generates their own secret)

if you can make copies of the thing that generates the codes it stops being something you have and becomes something you know, pretty much just another password, so it's not really 2FA since it's not a second factor

whether or not this actually matters in practice, who knows

Shaggar
Apr 26, 2006

ratbert90 posted:

Even better, Microsoft Authenticator is 100% compatible with the Google Authenticator.

goog auth is just totp which Microsoft auth supports but Microsoft auth also supports push which is superior.

Shaggar
Apr 26, 2006

Jenny Agutter posted:

I use it but is there a reason it doesn't support qr codes?

it definitely does

FlapYoJacks
Feb 12, 2009

Shaggar posted:

goog auth is just totp which Microsoft auth supports but Microsoft auth also supports push which is superior.

I do like push. It's quite convenient.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shame Boy posted:

if you can make copies of the thing that generates the codes it stops being something you have and becomes something you know, pretty much just another password, so it's not really 2FA since it's not a second factor

whether or not this actually matters in practice, who knows

if you can’t make a back up copy, the problem is “something you have” turns in to “something nobody has”

I’d wager that totp gets hosed up by people losing the secret way more than their secret falling into malicious hands

power botton
Nov 2, 2011

push it to the limit

power botton
Nov 2, 2011

mycrimes.mp4

https://www.youtube.com/watch?v=qk2jeE1LOn8

pseudorandom name
May 6, 2007

Cocoa Crispies posted:

if you can’t make a back up copy, the problem is “something you have” turns in to “something nobody has”

I’d wager that totp gets hosed up by people losing the secret way more than their secret falling into malicious hands

in conclusion, security is a land of contrasts

Rooney McNibnug
Sep 2, 2008

"Life always hopes. When a definite object cannot be outlined, the indomitable spirit of hope still impels the living mass to move toward something--something that shall somehow be better."
The Dialectics of SecFuck.

haveblue
Aug 15, 2005



Toilet Rascal

Cocoa Crispies posted:

if you can’t make a back up copy, the problem is “something you have” turns in to “something nobody has”

I’d wager that totp gets hosed up by people losing the secret way more than their secret falling into malicious hands

you can back up iphones locally with encryption through itunes sync, is that an option on android?

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

ratbert90 posted:

I do like push. It's quite convenient.

do you have authentication in your house?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

haveblue posted:

you can back up iphones locally with encryption through itunes sync, is that an option on android?

more people post in this thread than take local encrypted iPhone backups

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
check all your totp codes into github, problem solved

Adbot
ADBOT LOVES YOU

James Baud
May 24, 2015

by LITERALLY AN ADMIN
HasMyOTPbeenOwned.com


Oh my god, all my codes are in this dump!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply