Monday, February 25, 2008

Ponderings on "multi factor authentication" sillyness...

It seems like a disturbing trend:
Banks adding "more security" by adding extra "security questions"...

In short, the alleged idea is make your account more secure then just using your password (which is normally only known by you) by asking "personal trivia questions" related to high school mascots, car brands, maiden names,...

Whats wrong with that?


  • It's insecure by design. Most of this information is public! A potential attacker can guess or google this information. Different sites are also using the same questions.

  • It's extremely error-prone. What was that pet's name again?

  • It adds no extra phishing protection. A fake site can just as easily ask these questions together with your password.

  • Better solutions such as openid are publicly available, and allow the user to choose the level of security they prefer. Which can range from basic user-name password logins, over https client certificates to secure one-time key token-devices.


This (fairly cynical) post explains what I have been trying to get across way better that I did.

What to do when your bank forces you into this "Mickey mouse" scheme?
- Come up with a secondary password (preferable 2 "words")
- Fill it in as the "answer" to each question

This way, you are at least not decreasing the level of security provided.

Sunday, December 30, 2007

iPhone stress test

Picture taken at 3800M, -15C.

Slight discoloring, but nothing major.

I can't believe the things I do just to give accurate reviews!

Friday, November 23, 2007

More mile-high fun!

On a Virgin flight NY-SFO, I was trying out the various "Games" in the in-flight entertainment system. (I have a weird connection with those, more on that later).

One of the options was sort of "wheel of fortune" setup, where given a string of 7 random letters, and you scored points depending which words you could create out of it.

I was bummed to receive zero points for my 7 letter word, which not only should be in the dictionary, its also a great concept that I plan to license to Apple.

Thursday, October 25, 2007

Spot the terrorist!

The updated numbers are in! Currently there are over 755 thousand people on the terror watch list. All these people are deemed by our benevolent leaders too godless communist liberal dangerous to fly (but not enough to be arrested).

Other number: The current population of the US of A is 301,139,947.

A little math tell us that this translates to roughly 0.25% (1 in 400) being a "bad guy".

Personally, on any given week, I see hundreds of people. Dozens in the office, dozens in at the grocery store, hundreds just walking by. So... mathematically, I must have missed pointing out terrorist right next to me on several occasions!

This blatant personal carelessness about national security is shaming.

Henceforth, I hope you will join me in making our streets safer by publicly wrestling down and reporting to the police anybody who looks "suspicious", "dangerous", "different"!

I leave it to your personal threat assessment to choose what particular appearance attribute to discriminate guard against: Mustaches, skin/hair color,..

All is fair in love and war!

Only with your help can we make things safe and clean again! Do it or the terrorists win! Think about the children! God is with us!

Friday, October 19, 2007

iPhone 1.1.1 : Not all are equal

After successfully reverting a 1.1.1 firmware to 1.0.2 for a friend, guess what happened? Other friends asking for the same service of course!

Since the previous hack (my very first ever) was done while watching "Desperate Housewives", I figured "how hard can it be to do it again?" and agreed.

When going to the process, I did notice some differences:

  • While rebooting the screen showed a vague "mirror image" of the main screen
  • Instead of a small "Connect to iTunes" activation message during the restore process, I saw a (fairly gay) depiction of (what I assume) to be the same message. This one showed a iPhone apparently eager to be connected to a white cable.
But the biggest difference was that the "same" 1.1.1 OS now refused to be flashed with another version, whereas the previous phone was way more willing. This surprised me, because I was using the exact same hardware as I did before, USB cable included.

Wait a minute... exact same setup, "exact same" OS version (both 1.1.1) on the phone...
When quizzing the owner of the iPhone, it turned out that he had recently updated his iTunes installation.

So it seems to me that Apple got wind of the "downgrade hack" and silently patched iTunes to patch the iPhone to prevent it. All without asking for permission!

Moral of the story:
If you plan on being able to run custom application, do the move now, before any more "updates" sneak onto your system.


Apple Store