TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Congressman's phone password is 111111

321 pointsby breadandcrumbelover 5 years ago

23 comments

duxupover 5 years ago
I tell this story a lot. But I think in the time of smartphones and such it also represents the only real secure site I thought was truly secure from what I knew of it. This was before smartphones were common, but I think it was ahead of its time in that way.<p>I worked for a company that occasionally would service some of our hardware onsite. One customer was a company that did a lot of work for the military and they had &quot;that site&quot; that a few folks visited. Here was how that worked:<p>Nothing except your body and your clothes left the site, anything you brought stayed onsite (laptops that we brought onsite were left behind &#x2F; effectively disposable, later you couldn&#x27;t even bring those, they provided one). All that stuff belonged to the military &#x2F; whomever you interacted with at the site.<p>No electronics, cameras, etc that were not previously improved were allowed and you were told you would not be leaving anytime soon if you had something &quot;unexpected or unauthorized&quot;.<p>It was highly suggested that nothing was in your rental car other than your keys, the equipment you needed as they searched the car and the folks would take what they wished.<p>If you realized you had something you didn&#x27;t want to in the car it was highly suggested you do not turn around if you are at all close to the location and to drive up and immediately tell them you dorked up and brought something. This was a fairly remote location so the probabbly knew you were coming before you saw the gate and the guards didn&#x27;t like surprises.<p>Upon arrival you parked, were blindfolded and driven from the gate to the site, you never actually saw the outside of the site until you were in the building. You were never alone at anytime. Trips to the bathroom while at the site were monitored... in person by a guard with a rifle.<p>Now all that sounds ominous but everyone reported that the folks there were very professional (not friendly but professional).<p>The point of that whole story was that even a while ago someone said &quot;any electronics&quot; were a threat and decided that they had to go to extremes to limit their access. Still today I think that was the closest to a &quot;sure&quot; policy.
评论 #21345162 未加载
评论 #21347325 未加载
评论 #21344975 未加载
评论 #21345401 未加载
评论 #21344957 未加载
评论 #21346814 未加载
评论 #21345855 未加载
ydnaclementineover 5 years ago
I always thought that Android&#x27;s 3x3 dot pattern draw password thing was superior against these type of over the shoulder attack, as long as you turn off the tracing effect. Without tracing and if you do it quickly, it just looks like you’re dragging your thumb randomly all over the phone.
评论 #21345829 未加载
评论 #21345864 未加载
评论 #21345349 未加载
评论 #21345003 未加载
评论 #21345604 未加载
评论 #21345549 未加载
评论 #21345575 未加载
breakerboxover 5 years ago
If I were giving a security recommendation to famous people and congresspeople I would recommend using a password like this. You might think it’s incredibly insecure, but imagine this GIF contained that 6 digit number that the congressman uses for all of his accounts. Suddenly, a ton of other services and passwords are vulnerable to an attacker.<p>In reality a lot of iPhones now require authentication at the app level for apps that have sensitive data.<p>To each his own, but knowing how public you are and how many people would want your passcode, I think the best practice is to use something dumb like 6 of the same keys.
评论 #21345884 未加载
评论 #21348113 未加载
评论 #21346110 未加载
drtillbergover 5 years ago
The problem isn&#x27;t the password or the camera that captured it.<p>The problem is that the phone required a password in that scenario-- same user, phone never left his vicinity, probably not a long interval between uses. Being more selective about when to require a master password is a better protection model IMHO.
评论 #21345035 未加载
评论 #21345441 未加载
评论 #21345533 未加载
评论 #21345943 未加载
diafygiover 5 years ago
I wonder what AI tech is being developed around detecting pin code entry on phones using passive CCTV networks.<p>If you process the feeds for public transit security cameras, I wouldn&#x27;t be surprised if you can read the pin codes for a huge swath of the population. It would also reduce the need for law enforcement to try to get a suspect to tell them their passcode. Just look up that time they rode the subway 3 weeks ago and watch them enter it.
评论 #21345671 未加载
rvzover 5 years ago
That is a iPhone X like device, which only has Face ID or a PIN.<p>A PIN is more secure than a fingerprint and Face ID. But at least use a combination of either one with a PIN to make it more secure.<p>Since the device was already on and it directly showed the PIN screen, Face ID is disabled and instead he chooses to only use a very very weak PIN.<p>Oh dear.
评论 #21344603 未加载
评论 #21345581 未加载
评论 #21344672 未加载
onychomysover 5 years ago
So who is that? I&#x27;m not up on my random member of congress identification skills.
评论 #21346350 未加载
jdlygaover 5 years ago
Remind me to change the combination on my luggage
评论 #21345377 未加载
wayneftwover 5 years ago
I don&#x27;t lock my phone at all. Never have. However, with the new iPhones that don&#x27;t have a home button, I believe that Apple is forcing you to either use face unlock or a passcode. There is no choice to just leave it unlocked.<p>So, as soon as my iPhone 6s stops working, I will have to choose to: 1) Give in and use my face to unlock. 2) Use a dumb passcode like 000000. 3) Upgrade to the newest iPhone that still has a home button (I think iPhone 8) or 4) Become and Android user.
评论 #21345029 未加载
评论 #21344999 未加载
评论 #21345145 未加载
评论 #21345155 未加载
评论 #21345463 未加载
评论 #21345220 未加载
评论 #21347497 未加载
评论 #21345262 未加载
boonez123over 5 years ago
Looks like 777777 to me.
评论 #21346003 未加载
someonehereover 5 years ago
I worked for a well known company today, many years ago when it was smaller. When the IT team created new accounts for employees, it was the standard Pa$$word password for everyone. It was up to the user to change their password. They had no password rotating rules or requirements.<p>Anyway, many years later after I started, IT hires a person who wants to do good while in IT. This person discovers the CEO is still using the day one password he was given. The IT person decides to email the CTO, the director of IT, and the head of HR warning them the CEO is still using his default password.<p>I’m not clear what exactly the wording was, but the IT person skipping over the chain of command was bad enough it got them fired.
评论 #21348287 未加载
vulnover 5 years ago
Maybe the phone is attached to a MDM that requires a PIN.
评论 #21347622 未加载
dorfsmayover 5 years ago
The one thing I miss from CyanogenMod: keyboard key orders scrambled for each use.<p>I wish LineageOS and stock Android added that feature.
manigandhamover 5 years ago
Isn’t the real problem here that this was caught on video? Otherwise it’s just as secure as any other code.
评论 #21345329 未加载
评论 #21345355 未加载
评论 #21345291 未加载
ceejayozover 5 years ago
Aaaaaaand that&#x27;s why these things aren&#x27;t allowed in the SCIFs.
评论 #21344729 未加载
评论 #21344922 未加载
评论 #21344721 未加载
rezmepleaseover 5 years ago
this really illustrates how we live in a society
securingsincityover 5 years ago
I&#x27;m not an iPhone user but I thought that Apple warned you about this kind of password. It was covered quite a bit when Kanye was caught with a 000000 password when meeting with Trump.<p><a href="https:&#x2F;&#x2F;www.cnet.com&#x2F;news&#x2F;kanye-west-meets-with-trump-reveals-iphone-passcode-is-000000&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cnet.com&#x2F;news&#x2F;kanye-west-meets-with-trump-reveal...</a>
评论 #21345012 未加载
评论 #21344954 未加载
slgover 5 years ago
And yesterday over a dozen members of Congress barged into one of the Congressional versions of this site without authorization and while recording video, audio, and taking photos on their personal smartphones.<p>Here is a Twitter thread about why that is such a problem:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;MiekeEoyang&#x2F;status&#x2F;1187032800572125191" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;MiekeEoyang&#x2F;status&#x2F;1187032800572125191</a>
评论 #21346011 未加载
评论 #21346224 未加载
评论 #21345535 未加载
rerphaover 5 years ago
and they say millennials are on their phones too much!
dbg31415over 5 years ago
These are the people who are grilling Zuck?<p>Our communications, privacy, and security, are in good hands! Ugh.
评论 #21345576 未加载
_pmf_over 5 years ago
Still safer than using an off-brand or Smasung fingerprint sensor.
评论 #21345502 未加载
roenxiover 5 years ago
111111 is perfectly acceptable for a phone password. His password was just broadcast to the entire world; at least using 111111 means that he doesn&#x27;t have any illusions about how secure it is.<p>Phone passwords are for protecting things from your family.
评论 #21345522 未加载
评论 #21345264 未加载
评论 #21345387 未加载
tomatotomato37over 5 years ago
Yup, not sure why we expect good security practices out of a group who&#x27;s average age is 60
评论 #21344796 未加载
评论 #21344762 未加载
评论 #21344905 未加载