You can always use pihole to mess with your local dns and resolve to a fake website that looks like your social media of choice and collect their password
lol, warned 2 guys I worked with not to use the starbucks free wifi or any free wifi. One of them had their bank info compromised, the other had their google compromised.
Tv and app creators I feel like are also a bit responsible for this by not making it easy to do timed logouts when you log into a device for the first time. Unless you have a mental or physical checklist going its not a high priority
Most of the TVs that have apps like these in hotels specifically state on the login page that upon check out their system will automatically wipe your logins. At least in the several that I've used that have specific tight end apps like these. There are of course those cheap hotels that just have the Smart TVs in the rooms that you're free to log in as you wish as long as you remember to log out. Usually in those cases I won't log in at all or I may choose to log into like say Netflix if my kids are there and then are just remembered to log out. Of course I stay in a lot of hotels during the year as well. Think this year I'm already something like 20 or 25 nights in a hotel.
Both job and pleasure. I have family that lives out of state so I often go see them. My work takes me all over the West as well. And we like to go on adventures as well. I'm addition to the hotel nights we are at like 9 nights camping so far this year.
Briefly: look into sim swapping, which is the most obvious, day to day risk.
Then there's SS7 and how inherently trusting the whole system is.
Then depending on where you are, some mobile networks still have terrible link encryption (were talking so bad a normal laptop is enough these days to break it on the fly). Granted, this is rare these days, in part thanks to the efforts of Karsten Knohl, SRLabs and other security researchers who did a lot to shine a light on this and SS7
This is becoming less of an issue as US Mobile has anti-SIM-hijacking protection; hopefully other carriers will follow suit. Of course, the carriers themselves can still read your msgs, but so can WhatsApp, probably (despite their claims to the contrary).
Supposed to be 'Secure in Transit' though does nothing if you, as Saapas said, go to a sketchy site and reuse credentials. Data is so cheap today I have more data on my phone than I use a month on pc with live streaming, streaming yt, and playing online
Back when I was in college, I was young and dumb enough that I'd login to AIM on the college computers. (Nowadays I won't login to personal accounts on anything I don't fully control. I'm always surprised by coworkers who check their bank accounts, social media, personal email, etc. on their work laptops.)
Anyway, even at the time I was pretty good at logging out when I left each computer, but once I forgot. The next time I logged in, I was surprised to discover that my entire buddy list had been cleared. I never understood the motivation behind doing so. I don't think it was particularly funny but, even if it were, it's not like the perpetrator got to see my reaction or even to point and laugh.
I did learn a lesson from it, but presuming that that was the mission of whomever did it feels ... Generous.
Google doesn't give you codes. They don't even tell you that they enabled 2FA. If you log in on an android device, they will automatically enable it for 2FA, and for some reason they assume you will have access to this phone until the end of time, even if you haven't turned it on in months. The only way to go around this is to set up 2FA manually.
Google has locked so many people I know out of their accounts it's ridiculous.
Yeah if you're smart with the computor like me and you then you keep your 2FA backup somewhere. But if you're just a normal person, it doesn't occur to you. Google doesn't even do a very good job reminding you to properly set up 2FA in the first place.
I could take the locks off the door to my house but then I can’t be mad when I get robbed
Edit: I hope that the lesson learned is about needing to have multiple forms of MFA and a safe location for back up codes, like you would have multiple sets of keys and maybe a key box hidden in a safe place. Not blaming you for not realizing it at the time, it’s not something one would think about until it’s too late. It’s not like we had our parents to teach us about MFA best practices like you might have for house keys
And some people use those display units for social media for some reason.
Back in the 2010s I had a friend work in stores as a "device expert", he handled daily resets of the display units (this was pre-MDM easy management days). The number of people who just logged on to Twitter, Facebook Messenger, even WhatsApp or GRINDR of all things (yes, dude left his grindr account logged in, full of explicit images, which downloaded to the device's gallery, while the phones were most often used by KIDS in the store...), it was simply astonishing.
No it was USA only. We have three mobile carriers that own all the cell towers here. You’re either with Rogers, Bell, or Telus, or one of their derivatives. There’s zero competition here, it’s ridiculous.
A non-tech store had some iPhones and iPads on display. No internet. But it COULD connect to my phone hotspot. Wish I did something more than just download a rainbow six siege pic and set it as the wallpaper, but they took down that demo for I think close to a month.
I dont care for 2fa. Not interested in having my phone connected to my computer, and i dont like having an extra step when logging into stuff -- especially an extra step that needs me to use a second device. Id honestly rather risk getting hacked over ever having to use 2fa again.
Use a Yubikey. It's a small USB Device you can put on a keychain. It is still a second device, but it's not your phone. And you always have your keys with you, anyway.
I have no reason to believe that the google authenticator app on my google phone doesn't register and record that it's being used to log into XYZ website, and further that XYZ website is not then sending back unique identifying info to Google about me when ive used the code to log in.
I've lived with tech long enough to know that if they say "we absolutely don't," it really means they probably do.
Like when they swore up and down and gaslit us that our phones aren't listening to us to generate ads.
How many lies can I believe before I begin assuming everything is just another lie from a liar?
Guess im paranoid.
But that whole thing ignores that it's an annoying second step with another device. Like "you want to log in? Thread a needle with the string in your pocket first..."
MFA (a better term IMO for this) has nothing to go with phones, per se.
It's just about reducing risk by adding more proofs that the person claiming to have the right to do something has indeed the right to do something.
Unless you have excellent password hygiene (long, random, different for every single site and service) the likelihood of having an account taken over goes up quite fast. The overwhelming majority of the population doesn't, so forcing a second factor is a good way to limit damage.
If you don'tt like the multi step process, look at psskeys. They aren't perfect, but they offer nearly all the security benefits of MFA without having to go throughthrough multiple steps.
107 Comments
deceiver@infosec.pub · 222 pts · 39d
2FA won’t help if you leave a session running on a public device
greenMeanHoppinMachine@lemmy.world · 17 pts · 38d
That's the comment I was looking for.
Prathas@lemmy.zip · 2 pts · 38d
To be fair, we are in a specific community...
The_Hideous_Orgalorg@sh.itjust.works · 87 pts · 39d
Two factor would not help here. One needs to remember to log out of public devices before leaving them.
gandalf_der_12te@feddit.org · 18 pts · 39d
best to always use incognito browser on public devices. when you close the browser, it logs you off automatically.
PattyMcB@lemmy.world · 24 pts · 38d
Or just not be a moron and put your credentials into a random device in some store
VieuxQueb@lemmy.ca · 7 pts · 38d
Who knows what is running on that device AND router.
diabetic_porcupine@lemmy.world · 4 pts · 38d
Forreal I will never use a mfers WiFi
MrKoyun@lemmy.world · 3 pts · 38d
I mean, we have https now. Also VPNs. Wouldnt this make most situations secure?
diabetic_porcupine@lemmy.world · 1 pts · 38d
You can always use pihole to mess with your local dns and resolve to a fake website that looks like your social media of choice and collect their password
Anivia@feddit.org · 1 pts · 37d
Only if the user ignores the "unsafe connection" warning in the browser, since you won't have an SSL certificate for the domain
lost_faith@lemmy.ca · 3 pts · 38d
lol, warned 2 guys I worked with not to use the starbucks free wifi or any free wifi. One of them had their bank info compromised, the other had their google compromised.
guy@piefed.social · 2 pts · 38d
VPN ffs
lost_faith@lemmy.ca · 1 pts · 38d
At the time, when I warned against it, I was told that I was too paranoid. Guess I wasn't as paranoid as they thought
kuberoot@discuss.tchncs.de · 2 pts · 37d
Router doesn't matter if the device is trusted and the service you're using doesn't have shite security, with things like HTTPS.
hopesfall@lemmy.world · 3 pts · 38d
This is the way.
Rooster326@programming.dev · 1 pts · 38d
Why would you even log into a public device?
kevinsky@feddit.nl · 53 pts · 38d
The amount of people that leave things like youtube logged in on hotel room tv's is also moderately staggering.
Fedizen@lemmy.world · 11 pts · 38d
Tv and app creators I feel like are also a bit responsible for this by not making it easy to do timed logouts when you log into a device for the first time. Unless you have a mental or physical checklist going its not a high priority
titanicx@lemmy.zip · 4 pts · 38d
Probably because most the TVs are designed to auto logout after check out. So when you run into one that isn't it's weird.
Prathas@lemmy.zip · 12 pts · 38d
Interesting. I've actually never heard of them automatically logging out. That's partly why I am hesitant to log in in the first place.
titanicx@lemmy.zip · 1 pts · 37d
Most of the TVs that have apps like these in hotels specifically state on the login page that upon check out their system will automatically wipe your logins. At least in the several that I've used that have specific tight end apps like these. There are of course those cheap hotels that just have the Smart TVs in the rooms that you're free to log in as you wish as long as you remember to log out. Usually in those cases I won't log in at all or I may choose to log into like say Netflix if my kids are there and then are just remembered to log out. Of course I stay in a lot of hotels during the year as well. Think this year I'm already something like 20 or 25 nights in a hotel.
Prathas@lemmy.zip · 1 pts · 35d
Wow! Heavy traveling in your job?
titanicx@lemmy.zip · 2 pts · 35d
Both job and pleasure. I have family that lives out of state so I often go see them. My work takes me all over the West as well. And we like to go on adventures as well. I'm addition to the hotel nights we are at like 9 nights camping so far this year.
Sc00ter@lemmy.zip · 3 pts · 38d
We just stayed at a disney resort a few weeks ago. The tv prompted us to sign into OUR disney+ account...
macaw_dean_settle@lemmy.world · -11 pts · 38d
Ellipsis are wrongly used again. Why do you people keep using shit you do not understand?
adam_y@lemmy.world · 8 pts · 37d
Sc00ter@lemmy.zip · 7 pts · 37d
I used it to indicate my trailing thought. I had more written, but cut it off.
Also, no one cares about your grammar policing and it contributes nothing to the conversation
axx@slrpnk.net · 2 pts · 37d
It contributes nothing to the conversation…
RagingRobot@lemmy.world · 1 pts · 38d
Does it really matter to anyone other than the streaming companies?
If the next guy at the hotel watches my HBO why would I care?
Worst case scenario I lose my spot in a show.
Axolotl_cpp@feddit.it · 4 pts · 38d
And lose your account and your google account if it's youtube like the commenter said
Appoxo@lemmy.dbzer0.com · 2 pts · 38d
And your account.
houndeyes@toast.ooo · 51 pts · 39d
Kid looks like a Mad magazine cover.
ThunderQueen@lemmy.world · 39 pts · 38d
rangber@lemmy.zip · 33 pts · 38d
Wonder what Timothy is up to nowadays
Dkiscoo@lemmy.world · 25 pts · 38d
1337 h@xing the internets
P1k1e@lemmy.world · 4 pts · 38d
Tight
slaacaa@lemmy.world · 2 pts · 38d
https://www.nbcnews.com/news/us-news/actor-timothy-busfield-indicted-child-sex-abuse-charges-new-mexico-gra-rcna257502
sundray@lemmus.org · 32 pts · 39d
Ok, you've hacked me.
I hope you're ready for what you're about to see.
everett@lemmy.ml · 14 pts · 39d
Goat...
not@lemmy.dbzer0.com · 15 pts · 38d
se
PattyMcB@lemmy.world · 6 pts · 38d
The greatest of all time
[Kermit_puppet_goatse.jpg]
Hazel@piefed.blahaj.zone · 21 pts · 38d
"Hahaha hacked!!! ... now let me dox myself."
T00l_shed@lemmy.world · 14 pts · 38d
Maybe that's the name he uses so people think he is called timothy! And it wasn't a sprint store! Classic misdirects
ILikeBoobies@lemmy.ca · 19 pts · 38d
2fa wouldn't change anything and sms is an insecure system to begin with.
Hawke@lemmy.world · 0 pts · 38d
[citation needed] on the second half
ILikeBoobies@lemmy.ca · 14 pts · 38d
A big feature of sms is that it's not encrypted. Every tower that recieves the message is trusted to forward it unaltered. This is one attack avenue.
https://www.helpnetsecurity.com/2020/11/12/sms-voice-mfa/
Things like the following are generally recommended though Microsoft recommends using their app. https://www.yubico.com/
I should have clarified that sms 2fa is insecure not 2fa.
Hawke@lemmy.world · 6 pts · 38d
Okay that makes sense. Yes sms is insecure, not 2fa.
axx@slrpnk.net · 8 pts · 38d
Briefly: look into sim swapping, which is the most obvious, day to day risk.
Then there's SS7 and how inherently trusting the whole system is.
Then depending on where you are, some mobile networks still have terrible link encryption (were talking so bad a normal laptop is enough these days to break it on the fly). Granted, this is rare these days, in part thanks to the efforts of Karsten Knohl, SRLabs and other security researchers who did a lot to shine a light on this and SS7
Not sure how up to date it still is, but https://gsmmap.srlabs.de/ shows how unequal networks are.
Prathas@lemmy.zip · 1 pts · 38d
This is becoming less of an issue as US Mobile has anti-SIM-hijacking protection; hopefully other carriers will follow suit. Of course, the carriers themselves can still read your msgs, but so can WhatsApp, probably (despite their claims to the contrary).
Hawke@lemmy.world · -4 pts · 38d
That’s all sms though, not 2fa in general.
All valid points and good information within that scope.
Appoxo@lemmy.dbzer0.com · 1 pts · 38d
Are you an LLM?
Hawke@lemmy.world · 1 pts · 38d
It’s been edited, bud. Originally it said that 2fa in general is insecure.
Appoxo@lemmy.dbzer0.com · 2 pts · 38d
The edit icon is a bit not-obvious in Voyager...
And I can't view the original text.
Edit: Speeling on a phone is hard (read: annyoing)
Prathas@lemmy.zip · 3 pts · 38d
I don't think the original text before edits is viewable by anyone other than possibly instance admins.
TrickDacy@lemmy.world · 14 pts · 38d
Do you know what 2fa is?
Saapas@piefed.zip · 16 pts · 38d
It's like when people think VPNs will magically prevent their credentials from leaking while they're giving them to some sketchy website
TORFdot0@lemmy.world · 6 pts · 38d
But the YouTuber that sold me my VPN said it kept my online data safe (whatever that means)
lost_faith@lemmy.ca · 1 pts · 38d
Supposed to be 'Secure in Transit' though does nothing if you, as Saapas said, go to a sketchy site and reuse credentials. Data is so cheap today I have more data on my phone than I use a month on pc with live streaming, streaming yt, and playing online
toynbee@piefed.social · 12 pts · 38d
Back when I was in college, I was young and dumb enough that I'd login to AIM on the college computers. (Nowadays I won't login to personal accounts on anything I don't fully control. I'm always surprised by coworkers who check their bank accounts, social media, personal email, etc. on their work laptops.)
Anyway, even at the time I was pretty good at logging out when I left each computer, but once I forgot. The next time I logged in, I was surprised to discover that my entire buddy list had been cleared. I never understood the motivation behind doing so. I don't think it was particularly funny but, even if it were, it's not like the perpetrator got to see my reaction or even to point and laugh.
I did learn a lesson from it, but presuming that that was the mission of whomever did it feels ... Generous.
ThunderQueen@lemmy.world · 0 pts · 38d
toynbee@piefed.social · 8 pts · 38d
You shouldn't.
If the goal was to teach me a lesson, there were less destructive ways to do it.
If the goal was to troll, well, that's without redeeming qualities.
ThunderQueen@lemmy.world · 6 pts · 38d
toynbee@piefed.social · 2 pts · 38d
I agree that doing something non destructive is fine, if unnecessary.
ThunderQueen@lemmy.world · 0 pts · 38d
toynbee@piefed.social · 1 pts · 38d
All right then, "beneficial." To anyone involved.
ThunderQueen@lemmy.world · 1 pts · 38d
Devconsole@sh.itjust.works · 2 pts · 38d
Brown hat more like
possessedfaxmachine666@lemmy.world · 11 pts · 38d
sudo hack IP -127.0.0.1
CaptPretentious@lemmy.world · 4 pts · 38d
What, how'd you get my IP! You haxxor!?
HerbalGamer@sh.itjust.works · 9 pts · 38d
2fa got me locked out of google after losing my phone so fu2
theunknownmuncher@lemmy.world · 6 pts · 38d
You didn't print out or write down the codes they give you for this exact situation? 100% your fault and not 2FA's
HerbalGamer@sh.itjust.works · 3 pts · 38d
True but also I wasn't there when other people had to clear out my apartment so I didn't have much of a clue wether or not it would be saved.
Still know my pw managers pw by heart and have my gmail account pw written down but not that actual code, no.
PotatoesFall@discuss.tchncs.de · 0 pts · 38d
Google doesn't give you codes. They don't even tell you that they enabled 2FA. If you log in on an android device, they will automatically enable it for 2FA, and for some reason they assume you will have access to this phone until the end of time, even if you haven't turned it on in months. The only way to go around this is to set up 2FA manually.
Google has locked so many people I know out of their accounts it's ridiculous.
theunknownmuncher@lemmy.world · 4 pts · 38d
Tell it to my print out of emergency 2FA codes sitting in my documents safe.
https://support.google.com/accounts/answer/1187538
PotatoesFall@discuss.tchncs.de · 1 pts · 38d
Yeah if you're smart with the computor like me and you then you keep your 2FA backup somewhere. But if you're just a normal person, it doesn't occur to you. Google doesn't even do a very good job reminding you to properly set up 2FA in the first place.
TORFdot0@lemmy.world · 5 pts · 38d
Do you blame the locksmith if you lose your keys?
I could take the locks off the door to my house but then I can’t be mad when I get robbed
Edit: I hope that the lesson learned is about needing to have multiple forms of MFA and a safe location for back up codes, like you would have multiple sets of keys and maybe a key box hidden in a safe place. Not blaming you for not realizing it at the time, it’s not something one would think about until it’s too late. It’s not like we had our parents to teach us about MFA best practices like you might have for house keys
blimthepixie@lemmy.dbzer0.com · 9 pts · 38d
Logged into what?
What's a Sprint store?
If it's a shop that sells electronics like Currys or Mediamarkt then why would this person log into anything on display?
fonix232@fedia.io · 17 pts · 38d
Phone carrier.
They have display phones and tablets.
And some people use those display units for social media for some reason.
Back in the 2010s I had a friend work in stores as a "device expert", he handled daily resets of the display units (this was pre-MDM easy management days). The number of people who just logged on to Twitter, Facebook Messenger, even WhatsApp or GRINDR of all things (yes, dude left his grindr account logged in, full of explicit images, which downloaded to the device's gallery, while the phones were most often used by KIDS in the store...), it was simply astonishing.
jayands@lemmy.world · 4 pts · 38d
Sprint
iswas a phone carrier in North America (pretty sure just the US, but they may have been in Canadia, too)kboos1@lemmy.world · 6 pts · 38d
They're called T-Mobile now they merged or bought them, I don't remember. T-Mobile is owned by Deutsche Telekom
BurntWits@sh.itjust.works · 6 pts · 38d
No it was USA only. We have three mobile carriers that own all the cell towers here. You’re either with Rogers, Bell, or Telus, or one of their derivatives. There’s zero competition here, it’s ridiculous.
halfapage@lemmy.world · 9 pts · 39d
MidsizedSedan@lemmy.world · 8 pts · 38d
A non-tech store had some iPhones and iPads on display. No internet. But it COULD connect to my phone hotspot. Wish I did something more than just download a rainbow six siege pic and set it as the wallpaper, but they took down that demo for I think close to a month.
TropicalDingdong@lemmy.world · 7 pts · 39d
lolgottem
edgyspazkid@lemmy.wtf · 5 pts · 38d
A few days ago I though 2FA didn't worked for lemmy but I just didn't have timezone or something and that's why I couldn't login.
axx@slrpnk.net · 2 pts · 37d
Goated sounds disgusting.
dismay3915@lemmy.world · 5 pts · 38d
Lmao this is cute
spacegoat@lemmy.world · 3 pts · 36d
Timmy was later arrested and charged with violations of the CFAA, SCA, and ECPA. He faces 20 to life.
FudgyMcTubbs@lemmy.world · 2 pts · 38d
I dont care for 2fa. Not interested in having my phone connected to my computer, and i dont like having an extra step when logging into stuff -- especially an extra step that needs me to use a second device. Id honestly rather risk getting hacked over ever having to use 2fa again.
chloroken@lemmy.ml · 10 pts · 38d
This makes me mad but I have absolutely no justification. Like, it's your life. But I am incensed. Godspeed.
FudgyMcTubbs@lemmy.world · 2 pts · 38d
Thank you for the grace.
greenMeanHoppinMachine@lemmy.world · 6 pts · 38d
Use a Yubikey. It's a small USB Device you can put on a keychain. It is still a second device, but it's not your phone. And you always have your keys with you, anyway.
garbage_world@lemmy.world · -1 pts · 38d
axx@slrpnk.net · 2 pts · 38d
Please provide a source to justify the "likely steals your data" comment.
garbage_world@lemmy.world · 0 pts · 38d
axx@slrpnk.net · 1 pts · 37d
I'm sorry, I don't see how your reply answers my request for providing a source for your claim.
garbage_world@lemmy.world · 0 pts · 37d
Rooster326@programming.dev · 5 pts · 38d
He says having never dealt with having his identity stolen.
FudgyMcTubbs@lemmy.world · 3 pts · 38d
Correct. It solved a problem that didnt exist for me.
Honytawk@discuss.tchncs.de · 2 pts · 38d
Why do you think you need to connect your phone to your computer?
You do know you can just generate codes and neither device will know of the others existence, right?
FudgyMcTubbs@lemmy.world · 1 pts · 38d
I have no reason to believe that the google authenticator app on my google phone doesn't register and record that it's being used to log into XYZ website, and further that XYZ website is not then sending back unique identifying info to Google about me when ive used the code to log in.
I've lived with tech long enough to know that if they say "we absolutely don't," it really means they probably do.
Like when they swore up and down and gaslit us that our phones aren't listening to us to generate ads.
How many lies can I believe before I begin assuming everything is just another lie from a liar?
Guess im paranoid.
But that whole thing ignores that it's an annoying second step with another device. Like "you want to log in? Thread a needle with the string in your pocket first..."
hoppolito@mander.xyz · 7 pts · 38d
But then just don’t use google authenticator and instead one of the FOSS alternatives? Aegis comes to mind.
Like the original reply to your situation said, you do you - but this seems a weird threat model to me, extra-step point notwithstanding.
axx@slrpnk.net · 0 pts · 38d
MFA (a better term IMO for this) has nothing to go with phones, per se.
It's just about reducing risk by adding more proofs that the person claiming to have the right to do something has indeed the right to do something.
Unless you have excellent password hygiene (long, random, different for every single site and service) the likelihood of having an account taken over goes up quite fast. The overwhelming majority of the population doesn't, so forcing a second factor is a good way to limit damage.
If you don'tt like the multi step process, look at psskeys. They aren't perfect, but they offer nearly all the security benefits of MFA without having to go throughthrough multiple steps.
macaw_dean_settle@lemmy.world · -6 pts · 38d
That is not what 'hacked' means.
funkless_eck@sh.itjust.works · 21 pts · 37d
I'd counter this is exactly how a lot of hacking works
Jax@sh.itjust.works · 10 pts · 37d
Absolutely can be
ButteredBread@sh.itjust.works · 8 pts · 37d
JackbyDev@programming.dev · 8 pts · 37d
This is hacking. Just because it's a trivial attack vector that's easy to protect against doesn't mean it isn't.