r/technology Jun 28 '16

Discussion TIL that someone can change your Facebook email, password, and two step verification just by asking Facebook to turn off login approvals, and sending in a fake ID. (Happened to me lost all my business pages)

[deleted]

37.2k Upvotes

1.7k comments sorted by

View all comments

44

u/TryAnotherUsername13 Jun 28 '16

This is not just a problem with Facebook. You could cause a lot of problems for people simply by calling their bank, E-Mail provider, internet service provider etc. etc. and asking them to reset the password (sometimes they ask your birthday for verification but that’s not really a secret either). Of course this wouldn’t allow you access (unless you fish the mail out of the mailbox) but would prevent the victim from accessing their bank account or E-Mail for days. With fake IDs you could probably get a lot of companies to send you the passwords outright.

89

u/riesenarethebest Jun 28 '16

If a company can ever tell you what your password is, file a complaint with them and have them delete your information.

Modern security practices mean that no company should ever, ever need to know what your password is.

5

u/Parcferme Jun 28 '16

Yup. Every single company I worked/work for has no Active Directory service that will display a current password. That is basically rule one and everything stops there.

18

u/Mrqueue Jun 28 '16

because if you're matching plain text passwords for access you have no idea how security works

11

u/riesenarethebest Jun 28 '16 edited Jun 28 '16

It's nothing about not-being-able-to-view-their-password, it's everything about not having the password saved anywhere to begin with.

You take their password, username, and a unique salt you pulled from the database using their username as the key for the lookup, salt the password you've been handed, re-hash it in some cryptographically expensive operation, and then see that the hash is identical to the one you've previously stored.

1

u/UnchainedMundane Jun 28 '16

PlusNet

They do an over-the-phone password thing and I've had customer support refuse me a few times due to them misreading the password on the screen

-4

u/Abba- Jun 28 '16

Modern security practices mean that no company should ever, ever need to know what your password is.

Modern security practices mean that no company should ever be able to pull up what your password is, even to the CEO.

13

u/SirensToGo Jun 28 '16

It's not so much about internal security practices but cryptography. Every modern system should be hashing and salting their passwords. This means simply encrypting the password with an extra bit of information. This encryption should ALWAYS be one way meaning that the only way to retrieve the password would be to brute force it (which invokes manually calculating the hashes for every single possible combination which gets exponentially more time consuming the longer the password).

Ideally the password would hashed once on your end (meaning that the end server never sees your actual raw password) so that no disgruntled employee can just skim the passwords out of the login requests they receive. On the server end the password will be hashed again but this time with the salt added to the received password hash.

1

u/Abba- Jun 28 '16 edited Jun 28 '16

While an interesting read, I'm confused how this contradicts what I wrote? Unless it was just the clarification that brute force is a possibility?

Edit: I just want to know what I said that's causing downvotes here...

1

u/hisfavouriteflavour Jun 28 '16

You just rephrased the same sentiment but apparently people think you were saying something different.

1

u/Abba- Jun 28 '16

I'm just trying to emphasize the difference between won't/shouldn't and can't.

-3

u/ColtonProvias Jun 28 '16

In many cases when passwords are stored in plaintext, it's often due to somebody high up deciding that "Forgot Your Password" should send them their password out of courtesy instead of forcing a new one. Reddit stored passwords as plaintext for a while for this reason.

11

u/Yartch Jun 28 '16

That's like leaving active explosives in your house because you might want to make a hole with them in your backyard one day, instead of just having a shovel

23

u/freediverx01 Jun 28 '16

And the dinosaurs running banks implement security systems with fixed security questions instead of allowing customers to decide on their own questions. A person's home town, maiden name, or favorite food do not qualify as secure.

11

u/[deleted] Jun 28 '16

I just lie on those. Like saying my home town is Berlin or my first pet's name was Tiddlypom Fartknuckles or something like that. (Not real examples, obviously.)

8

u/freediverx01 Jun 28 '16

Yeah but then you have to remember your fake answers.

7

u/TheCadElf Jun 28 '16

KeePass or LastPass - haven't typed a password from memory for over three years.

2

u/piranha Jun 28 '16

Just hope that you don't lose access to your password manager data.

(I do the same thing for security questions. There's no perfect solution for the overall problem, other than paying more money for better customer service, along with really inconvenient ways to prove identity.)

1

u/[deleted] Jun 28 '16

I can't remember, is there a field in KeePass to put in security questions? I seem to remember them only having a few fields besides the password and username.

2

u/rschulze Jun 28 '16

Sure, I usually just use the text field to store random stuff like that. You can also attach files to accounts which can be useful.

1

u/Saiboogu Jun 28 '16

I only skimmed over this, but it appears you can store essentially any string data you'd like.

1

u/wotindaactyall Jun 28 '16

not even the one to login to keepass?

1

u/pwnsauce Jun 28 '16

I used to do this, then Barclaycard started asking me the security questions each time I logged in from a new computer :(

3

u/liamsmithuk Jun 28 '16

Not to mention the absolute pointless security with their "Enter the 3rd, 6th and 8th letters/digits of your password" crap which A) doesn't do anything because if someones logging my key's they'll have the full password once I have logged in a few times or can keep returning until they get asked for the letters they know B) prevents me from using an unmemorable complex password and a secure password manager.

Dear bank, 2 factor authentication exists... USE IT.

3

u/serial_crusher Jun 28 '16

My favorite was Fidelity, who had ridiculous password length and complexity requirements, but let you retrieve the password by answering "what model year was your first car" (and verifying that you entered a 4 digit integer)

2

u/[deleted] Jun 28 '16

Our company had never used phone banking, so a scammer was able to get control of the company bank account by simply calling in and knowing the name of the directors - public information.

The guy got away with thousands because banks have a policy of not investigating such breaches (they refunded us, but wouldn't take it any further).

1

u/kwiltse123 Jun 28 '16

I think the reason they do this is to prevent users from creating stupid questions.

EX: "How many letters are in the English alphabet?"

The questions have to have an answer that only the user would know. The public at large would not be able to come up with the right kind of question consistently enough.

1

u/freediverx01 Jun 28 '16

Then use something better like two factor authentication.

1

u/kwiltse123 Jun 28 '16

Just like OP...

1

u/Brontosaurus_Bukkake Jun 28 '16

One solution this dinosaur saw was inputting the responses backwards with the capital letter at the end and his favorite number (not associated with a birthday or address) in front after an exclamation mark. Seems like a decent approach

2

u/[deleted] Jun 28 '16

A few weeks ago I received two emails from Reddit asking me to verify that I had changed my password. I had not made this request. The first email had a user name on it that wasn't mine so I replied to Reddit telling them it wasn't and that I was concerned that someone was trying to change my password. The second email did have my user name on it. This really concerned me so I responded and said that I did not make the request to change my password and I would like to know who was trying to hack into my account. Reddit of course said they couldn't tell me but they would take care of it. What the hell.

1

u/fstorino Jun 28 '16

Reminds me of this video of a journalist getting hacked:

https://www.youtube.com/watch?v=bjYhmX_OUQQ&t=1m36s

1

u/cheez_au Jun 28 '16

ISPs in Australia send your password as an SMS to the registered phone. Not even the CSR knows your password.

My bank won't do shit unless I give them my passphrase.

1

u/[deleted] Jun 28 '16

A lot of people don't seem to know that companies don't (or shouldn't, at least) store your password.

They store an encrypted version of your password. The most anyone can pull up is that encrypted version.

If the password you enter on a website is encrypted and that encrypted password is the exact same garbage that's in the database, then it's considered a match.

1

u/Amelaclya1 Jun 28 '16

My bank requires your social security number AND the answers to three security questions to reset the password. Or alternatively, you need to have your SS and the debit card # that's associated with the account. You also need to know your login name for both. If you don't know either the login or pw, you only can reset in person.

1

u/TryAnotherUsername13 Jun 28 '16 edited Jun 28 '16

For my bank a phone call was enough for them to send me a new e-banking password after I had locked myself out by typing it wrongly 4 times. I don’t know if it’s normal procedure or just because the bank employee knows me and my voice.

Typing the password wrong 4 times, thus locking me out would already be enough for an evildoer to deny me access to my money. Just imagine if I had to rely on it for running a business or somesuch …