TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

When two-factor authentication is not enough

284 点作者 ab9大约 11 年前

13 条评论

kijin大约 11 年前
Although Gandi.net is a fantastic company, their security practices are nothing to write home about.<p>A few years ago, one of my clients lost access to her Gandi.net account. Unfortunately, she had the &quot;disable password resets via email&quot; option set in her account. That should have given her quite a headache, right?<p>Nope. I, an independent contractor who didn&#x27;t even own the account, was able to convince Gandi support to disable that option so that she could reset her password via email. They didn&#x27;t even ask for any documents to prove either my identity or my client&#x27;s. It took several days, but the only reason it took so long was because their English support was very slow back then.<p>So I&#x27;m not surprised that Gandi let the attacker change the email on FastMail&#x27;s account when presented with genuine-looking documents.<p>And this is not a problem that is specific to Gandi. Even with other online services, it&#x27;s often quite easy to bypass automated security measures if you go through a human being, whether through the support system or through good ol&#x27; snail mail. In fact, I&#x27;m sure that snail mail is by far the most reliable way to take over someone else&#x27;s account nowadays. So many of us in the tech industry have no idea how to verify the authenticity of a piece of paper, especially if it&#x27;s from a different country.<p>Meanwhile, another favorite web host and registrar of mine, NearlyFreeSpeech.net, recently enabled two-factor authentication. But they did it differently. In addition to OATH TOTP, NearlyFreeSpeech allows you to select several other tests that you need to pass in order to recover your account. If you tell them to give you six different tests, which will probably take several weeks because some of the tests involve snail mail, they&#x27;ll honor your preferences. Or you can choose to take four tests. Or three. Or two. It&#x27;s your choice. That&#x27;s multi-factor auth done right.
评论 #7565110 未加载
评论 #7570074 未加载
ghshephard大约 11 年前
It&#x27;s interesting how there are people who think spending $100&#x2F;year&#x2F;domain is a lot of money - but when your entire company&#x27;s business&#x2F;value is on the line, I would think that spending $1,000&#x2F;year&#x2F;domain, to make absolutely sure nothing goes wrong, would be a bargain.<p>It also ensures that your registrar has the resources required to guarantee a very high level of verification and due process to ensure that everything is done correctly, with lots of extra human review (in addition to all of the automated safety checks, not instead of)<p>I&#x27;ve heard good things about <a href="https://www.markmonitor.com/" rel="nofollow">https:&#x2F;&#x2F;www.markmonitor.com&#x2F;</a> when it comes to managing domains (among other things)
评论 #7564866 未加载
评论 #7564848 未加载
评论 #7569056 未加载
评论 #7564871 未加载
Revisor大约 11 年前
This article really should have been called &quot;Security hole in Gandi&#x27;s processes&quot;. Why would they change the account email address if you didn&#x27;t reply to a single email within 24 hours? Who thought that was a good solution?
评论 #7564856 未加载
评论 #7564858 未加载
评论 #7564992 未加载
rdl大约 11 年前
I wish there were a &quot;pro registrar&quot; who handled domains, ssl certs, etc for people who actually value their business. Right now, the best you can do is probably become an ICANN registrar yourself (since all the registrars seem to be assclowns from a security or support perspective, or both), and get an intermediate ca (if needed) or manage your certs through something like venafi. That is maybe a $100k setup, $50k&#x2F;yr cost.<p>Someone less than that, or for that price but without having to devote staff, would make sense for some customers.<p>Sort of like MarkMonitor, I guess.
jrochkind1大约 11 年前
That email message from Gandi is _so_ confusing, at first I thought the story was going to be about how it was a phishing attempt!<p>&gt; <i>If you can read this message, then you can recover the password of your account, and thus modify the email address of the handle. In that case, we won&#x27;t take care of your request.</i><p>Wait... what?
biot大约 11 年前
I&#x27;ve been a fan of easyDNS for their security features and how they go to bat for their customers when it comes to things like transfers &#x2F; takedown notices.<p><a href="http://blog.easydns.org/2014/01/29/welcome-to-easydns-press-1-for-support-press-2-to-get-the-last-4-digits-of-your-credit-card-number-on-file-here/" rel="nofollow">http:&#x2F;&#x2F;blog.easydns.org&#x2F;2014&#x2F;01&#x2F;29&#x2F;welcome-to-easydns-press-...</a><p><a href="http://blog.easydns.org/2012/02/21/the-official-easydns-domain-takedown-policy/" rel="nofollow">http:&#x2F;&#x2F;blog.easydns.org&#x2F;2012&#x2F;02&#x2F;21&#x2F;the-official-easydns-doma...</a><p>And has Gandi changed their terms recently to remove the bullshit? <a href="https://news.ycombinator.com/item?id=4970947" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=4970947</a>
danielweber大约 11 年前
Online games separate your public handle from your login username (typically your email address). If someone wants to take over LazerBob, they have to first guess his username.<p>It&#x27;s nowhere near sufficient by itself, but it cuts down on the noise dramatically.<p>Many email addresses should be considered sensitive, in that you want any attempt to talk to them to get close personal attention from several senior people. &quot;hostmaster@fastmail.fm&quot; should be changed to &quot;hostmaster-9508gdgs42x@fastmail.fm&quot; simply to reduce the amount of noise going to it. Don&#x27;t publish it in your whois or on your blog; tell it only to your domain manager.<p>You can&#x27;t count on it staying secret forever, of course.
ams6110大约 11 年前
<i>If you are opposed to this modification, thank you for letting us know only by replying to this email.<p>If you can read this message, then you can recover the password of your account, and thus modify the email address of the handle. In that case, we won&#x27;t take care of your request.</i><p>I get that they are not native English speakers, but if I got an email like that I&#x27;d be VERY likely to conclude that it was phishing and ignore it. It just reads like so many of those broken-English &quot;Kind Sir, your email quota has been exceeded, please to click here to revalidate your password account&quot; mails I get every other day.<p>Hire an English speaking writer to draft your email notices.
kmfrk大约 11 年前
I&#x27;m currently using <a href="https://iwantmyname.com" rel="nofollow">https:&#x2F;&#x2F;iwantmyname.com</a> for my active domains, but I would like to hear people&#x27;s experiences with it.
richardwigley大约 11 年前
The passport will be obviously forged. A hacker won&#x27;t have even done a good job it doesn&#x27;t matter because people don&#x27;t check. This process was described in a candid interview with a hacker that tried to take over the interviewers website - in it he points out that social engineering is the easiest way around security. <a href="http://shoptalkshow.com/episodes/special-one-one-hacker/" rel="nofollow">http:&#x2F;&#x2F;shoptalkshow.com&#x2F;episodes&#x2F;special-one-one-hacker&#x2F;</a>
评论 #7573181 未加载
Schwolop大约 11 年前
The article links to a Schneier article which suggests using random keyboard mashing as an answer to &quot;Security&quot; questions. This is all well and good until you need to use the Australian Government Centrelink application, in which not one, but FIVE &quot;Security&quot; questions are requested.<p>And then, without any warning, you&#x27;re obliged to provide your password AND the answer to a random one of those questions when you log in.<p>Guess how long I was on hold for...
j-rom大约 11 年前
Multiple forms of authentication do not ensure security. They merely raise the bar for the effort it takes to break it.
dawson大约 11 年前
Can anyone recommend a registrar who takes domain security seriously? (think, £ six digit value domain names)
评论 #7566679 未加载
评论 #7565242 未加载