zlacker

[parent] [thread] 11 comments
1. red_ad+(OP)[view] [source] 2018-09-28 17:12:53
I find facebook's effects on privacy and democracy as scary as the next person, but so far their secure coding standards have been extremely high. They're one of the few big names NOT on haveibeenpwned.com, they run their passwords through a KDF and then encrypt the result with a hardware security module, and a whole lot of other good things.

I guess even the best (at secure coding) sometimes mess up.

replies(4): >>51lver+7k >>saagar+uv >>ern+0M >>Smelly+1a1
2. 51lver+7k[view] [source] 2018-09-28 19:25:58
>>red_ad+(OP)
Many users are still going to use the same password for their FB account and email account. All the security in the world won't fix people.
replies(1): >>ilaksh+lo
◧◩
3. ilaksh+lo[view] [source] [discussion] 2018-09-28 19:59:16
>>51lver+7k
Pervasive biometric security may be the next step. I know it's scary and could actually be abused but it also can generally increase the level of security for everyone.
replies(2): >>lurker+hz >>soroko+wk1
4. saagar+uv[view] [source] 2018-09-28 20:55:05
>>red_ad+(OP)
The issue is that Facebook has access to so much information that their security has to essentially be unbreakable if they don’t want a massive leak of sensitive user information.
◧◩◪
5. lurker+hz[view] [source] [discussion] 2018-09-28 21:32:09
>>ilaksh+lo
If your password is leaked, then you can still reset it. If your fingerprint signature leaks, you're out of options.
replies(1): >>why_on+RL
◧◩◪◨
6. why_on+RL[view] [source] [discussion] 2018-09-29 00:19:36
>>lurker+hz
Burn your fingers!
replies(1): >>red_ad+Z81
7. ern+0M[view] [source] 2018-09-29 00:22:13
>>red_ad+(OP)
They're one of the few big names NOT on haveibeenpwned.com

Have Amazon, Google, Twitter, Microsoft or Apple been on haveibeenpwned? That’s what I think of when I hear “big names”.

replies(1): >>koko77+da1
◧◩◪◨⬒
8. red_ad+Z81[view] [source] [discussion] 2018-09-29 09:14:21
>>why_on+RL
This may be an urban legend, but I've heard there was once a bank robber who dipped his fingertips in acid. After a few months, his fingers healed, and the prints were exactly the same as before.
9. Smelly+1a1[view] [source] 2018-09-29 09:39:27
>>red_ad+(OP)
The fact that passwords have never been leaked is irrelevant when a hacker can just get hold of the access tokens!
◧◩
10. koko77+da1[view] [source] [discussion] 2018-09-29 09:42:27
>>ern+0M
MS yes, via LinkedIn (at least)
replies(1): >>manque+mc1
◧◩◪
11. manque+mc1[view] [source] [discussion] 2018-09-29 10:32:34
>>koko77+da1
Not the same.. that breach was way before the acquisition, you can't conclude from that breach that MS development or security practices were lacking ..
◧◩◪
12. soroko+wk1[view] [source] [discussion] 2018-09-29 13:18:16
>>ilaksh+lo
Something like left eye iris scan for Google, right eye iris scan for FB, left index fingerprint for AWS?
[go to top]