TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Why is company letterhead a valid form of auth in 2022?

41 点作者 tjstebbing将近 3 年前
After filing a violation with twitter support for an account impersonating an opensource project I work on (posting fake news, etc) Twitter has asked that I verify myself as being part of the organisation being impersonated by providing a copy of my business card or a signed company letterhead.<p>This is not the first time I&#x27;ve been challenged to provide a company letterhead as a form of authentication by a large, reasonably sophisticated company. How is this still considered quality best practice?

14 条评论

londons_explore将近 3 年前
You&#x27;ve gotta split it into &#x27;technical auth&#x27; and &#x27;legal auth&#x27;.<p>Legal auth is simply making sure they can sue you, and&#x2F;or get you sent to prison if you circumvent their system.
评论 #32507879 未加载
评论 #32508502 未加载
ksaj将近 3 年前
I have as well. Even a really long time ago, so it sounds like a long lasting habit.<p>It reminds me of how lawyers are happy to accept signatures by fax. You could be a rather lousy forger, yet because of the huge and extremely black pixels, still make a passable forged signature over fax. You can even tape a real signature on the page, or make numerous corrections, because the resolution simply cannot show any of those details. There is not much one would consider reliable about a faxed document.
评论 #32508485 未加载
jiveturkey将近 3 年前
Twitter is one (of several) companies that have used your required phone number for marketing purpose. How is it you think they have any care about best practices?<p>Anyway, this is about shifting liability with minimal effort. As such, I&#x27;d consider it best practice. Of course, I&#x27;m using that term in a different way than you, but you just need to appreciate the goal here. It&#x27;s not at all about &quot;authenticating&quot; you as a heretofore unknown, authorized member of the org -- that&#x27;s <i>extremely</i> difficult, even at small scale.
Anderkent将近 3 年前
It takes pretending to be someone you&#x27;re not from &#x27;a prank&#x27; to &#x27;fraud&#x27;, and as such is actually valuable
sokoloff将近 3 年前
I’ve been particularly amused by this, given that I work at a company which prints BCs and letterhead.
outsidetheparty将近 3 年前
I mean... we still use physical signatures, too. Old habits die hard.<p>But I suspect this has a lot more to do with proving that you are explicitly representing yourself to them as a member of the organization; not proving that you actually are part of the organization.
refurb将近 3 年前
What do you propose they ask for instead?<p>Plenty of &quot;open source projects&quot; are nothing more than some informal group working together. It&#x27;s not like they are registered with the government.
评论 #32509021 未加载
dazc将近 3 年前
Same way a passport is, I guess? 99% of organisations that ask for a passport image have no way of knowing whether it is fake or not, a letterhead is slightly easier to mock up though.
评论 #32506842 未加载
评论 #32506801 未加载
aborsy将近 3 年前
Keybase had a good system for authentication. You link your public key to multiple accounts, and use private key to prove your identity.<p>That seems more secure than physical signatures and letter heads, that can presumably be easily forged.<p>But Keybase seems not developed anymore. Does anyone know what’s the situation?
ggm将近 3 年前
BGP speakers still discuss &quot;letter of authority&quot; despite RPKI being a thing for a decade.
skywhopper将近 3 年前
Simple answer is: Because there is literally no way to do it, and this <i>used</i> to be a reasonable approach before cheap hi-res printers became available.
tiahura将近 3 年前
Can you cite examples of this method of authentication being defeated?
LatteLazy将近 3 年前
Because it was the best idea someone had in 1950. And humans don&#x27;t learn, you just wait for the old ones to die and new ones to enter the workforce with new ideas.
freedude将近 3 年前
A better question might be why is a company considered a legal entity or even a technical entity? It has been said that they shouldn&#x27;t be and that legality should rest with the individual companies&#x27; owner. This of course would end corporations and much of the crap they produce and force owners to be accountable to their word. Yes, a novel concept.<p>But don&#x27;t take my word for it. Read what Adam Smith had to say about it first in the Wealth of Nations. <a href="https:&#x2F;&#x2F;www.ibiblio.org&#x2F;ml&#x2F;libri&#x2F;s&#x2F;SmithA_WealthNations_p.pdf" rel="nofollow">https:&#x2F;&#x2F;www.ibiblio.org&#x2F;ml&#x2F;libri&#x2F;s&#x2F;SmithA_WealthNations_p.pd...</a>
评论 #32514156 未加载