Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

Brain fried -- Core dumped


computers / comp.misc / Using SMS for password reset.

SubjectAuthor
* Using SMS for password reset.Sylvia Else
+* Re: Using SMS for password reset.Dan Purgert
|+* Re: Using SMS for password reset.Sylvia Else
||`* Re: Using SMS for password reset.Bruce Horrocks
|| +- Re: Using SMS for password reset.Kerr-Mudd, John
|| `- Re: Using SMS for password reset.Ian
|`* Re: Using SMS for password reset.Spiros Bousbouras
| +- Re: Using SMS for password reset.D
| +* Re: Using SMS for password reset.Julieta Shem
| |`* Re: Using SMS for password reset.Mike Spencer
| | `- Re: Using SMS for password reset.Julieta Shem
| `* Re: Using SMS for password reset.Dan Purgert
|  +* Re: Using SMS for password reset.Sylvia Else
|  |`- Re: Using SMS for password reset.Dan Purgert
|  `* Re: Using SMS for password reset.Spiros Bousbouras
|   `* Re: Using SMS for password reset.Dan Purgert
|    `- Re: Using SMS for password reset.Spiros Bousbouras
+- Re: Using SMS for password reset.Rich
+- Re: Using SMS for password reset.newsmaster
`* Re: Using SMS for password reset.Sylvia Else
 `* Re: Using SMS for password reset.Rich
  +- Re: Using SMS for password reset.Bob Eager
  +* Re: Using SMS for password reset.Julieta Shem
  |`* Re: Using SMS for password reset.Scott Dorsey
  | `* Re: Using SMS for password reset.Julieta Shem
  |  `- Re: Using SMS for password reset.D
  `- Re: Using SMS for password reset.Sylvia Else

Pages:12
Using SMS for password reset.

<l1rpu5FbrprU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3367&group=comp.misc#3367

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: sylvia@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: Using SMS for password reset.
Date: Tue, 30 Jan 2024 19:22:29 +1100
Lines: 33
Message-ID: <l1rpu5FbrprU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
X-Trace: individual.net zgVMwbdhaJs0Vo+vT7emCQF49sWH2OYCdV2rZhJIqfh2Hv2WVD
Cancel-Lock: sha1:3zFQJwBVmJyQ7pbGyIimEUIJTNc= sha256:B9Mtq8uV7L5KXc2Wb6ICNRV6PLO2oE8wyAY/d34niK0=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Content-Language: en-US
 by: Sylvia Else - Tue, 30 Jan 2024 08:22 UTC

This is really a rant - venting to release some of the frustration.

I'm in the process of selling my house, and I need somewhere secure to
hold the proceeds. I decided I'd create a account with a bank I don't
otherwise bank with, and interact online with it using a live-DVD on a
system that has no storage. So no risk of key loggers or other hacks.
I'd remember the strong password, and not have it written down anywhere.

Except that the banks insist on having a password reset option,
validated using an SMS. This undermines my attempts at ensuring that the
account remains secure.

I've tried telling banks (and other entities, indeed) that I don't want
the ability to reset the password. No go, because such an option is not
implemented in their systems.

Telcos in Australia have some quite strict rules regarding transfer of
mobile phone numbers, but the rules still get broken, and frauds
committed thereby.

If someone perpetrated a fraud as a consequence of the SMS password
reset, I'd have a good case that it was a fraud against the bank, rather
than against me, and that it was therefore the bank's loss.

Still, I'd rather not have to deal with it.

I looked at having a SecurIDĀ® device as 2FA. But guess what? It can be
used to reset the password.

So I'm tearing my hair out. Why do banks have this huge blind-spot when
it comes to resetting passwords?

Sylvia.

Re: Using SMS for password reset.

<slrnurhkif.2h7.dan@djph.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3368&group=comp.misc#3368

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!usenet.network!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dan@djph.net (Dan Purgert)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 17
Message-ID: <slrnurhkif.2h7.dan@djph.net>
References: <l1rpu5FbrprU1@mid.individual.net>
Injection-Date: Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="51f5a4e53894cd73e10b64e117b15a09";
logging-data="1011666"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18fu5wQvyVgxjMd8zjBDNuNQ9yBbtj/0GQ="
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:gMTY+SOxQcp7UPkRXeDNB9amHas=
 by: Dan Purgert - Tue, 30 Jan 2024 10:39 UTC

On 2024-01-30, Sylvia Else wrote:
> This is really a rant - venting to release some of the frustration.
>
> I'm in the process of selling my house, and I need somewhere secure to
> hold the proceeds. I decided I'd create a account with a bank I don't
> otherwise bank with, and interact online with it using a live-DVD on a
> system that has no storage. So no risk of key loggers or other hacks.
> I'd remember the strong password, and not have it written down anywhere.

Until you don't remember it, then what?

Because let's face it, eventually we all forget the password.

--
|_|O|_|
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1 E067 6D65 70E5 4CE7 2860

Re: Using SMS for password reset.

<l1s2vuFbs14U1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3369&group=comp.misc#3369

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: sylvia@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 21:57:02 +1100
Lines: 24
Message-ID: <l1s2vuFbs14U1@mid.individual.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net U3Sy3CPmp0vihnYyY2YyngINkEkyk2ghk6wb0dwIXM3m3z3A20
Cancel-Lock: sha1:o84XZVCNBD7jXlKgTeyvmO280PQ= sha256:8XUKPfn6wxzybaP7YAnqhtqXFHIUzXD9XEibo076f/E=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Content-Language: en-US
In-Reply-To: <slrnurhkif.2h7.dan@djph.net>
 by: Sylvia Else - Tue, 30 Jan 2024 10:57 UTC

On 30-Jan-24 9:39 pm, Dan Purgert wrote:
> On 2024-01-30, Sylvia Else wrote:
>> This is really a rant - venting to release some of the frustration.
>>
>> I'm in the process of selling my house, and I need somewhere secure to
>> hold the proceeds. I decided I'd create a account with a bank I don't
>> otherwise bank with, and interact online with it using a live-DVD on a
>> system that has no storage. So no risk of key loggers or other hacks.
>> I'd remember the strong password, and not have it written down anywhere.
>
> Until you don't remember it, then what?
>
> Because let's face it, eventually we all forget the password.
>

If I say I won't forget, you've no real reason to doubt me. There are
many things that I've remembered for decades.

In the event that I really did forget, then I'd have to show up at one
of the bank's offices with physical identity documents.

Sylvia.

Re: Using SMS for password reset.

<L2PlxvxSHEVJx+H9A@bongo-ra.co>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3370&group=comp.misc#3370

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.nntp4.net!news.hispagatos.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: spibou@gmail.com (Spiros Bousbouras)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 14:33:58 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 24
Message-ID: <L2PlxvxSHEVJx+H9A@bongo-ra.co>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 30 Jan 2024 14:33:58 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="6c24822ffc75d1de6fc33aa0d57c2f14";
logging-data="1088482"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/6ewlhNXMBZ8UqZL5C/rWW"
Cancel-Lock: sha1:EQ1m/CVRlAPdRba9IHEapZnBg0c=
In-Reply-To: <slrnurhkif.2h7.dan@djph.net>
X-Server-Commands: nowebcancel
X-Organisation: Weyland-Yutani
 by: Spiros Bousbouras - Tue, 30 Jan 2024 14:33 UTC

On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
Dan Purgert <dan@djph.net> wrote:
> On 2024-01-30, Sylvia Else wrote:
> > This is really a rant - venting to release some of the frustration.
> >
> > I'm in the process of selling my house, and I need somewhere secure to
> > hold the proceeds. I decided I'd create a account with a bank I don't
> > otherwise bank with, and interact online with it using a live-DVD on a
> > system that has no storage. So no risk of key loggers or other hacks.
> > I'd remember the strong password, and not have it written down anywhere.
>
> Until you don't remember it, then what?
>
> Because let's face it, eventually we all forget the password.

That's a very presumptuous thing to say. I have my own ways of storing and
retrieving passwords (which may include just my memory) and I'm confident
they are secure and reliable enough. So don't include me in your "we".

I share Sylvia's frustration and it's not just with banks. Pretty much any
online site with an option to create an account , will also have some kind
of password reminder , usually sent to your email. Very often I have wished
for sites to offer the option when creating an account to disable any
password reminders but I have yet to see a site which does this.

Re: Using SMS for password reset.

<9815dfa4-3b70-85f6-8f3d-e4486f2cd123@example.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3371&group=comp.misc#3371

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!.POSTED!not-for-mail
From: nospam@example.net (D)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 16:38:00 +0100
Organization: i2pn2 (i2pn.org)
Message-ID: <9815dfa4-3b70-85f6-8f3d-e4486f2cd123@example.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net> <L2PlxvxSHEVJx+H9A@bongo-ra.co>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Injection-Info: i2pn2.org;
logging-data="1096190"; mail-complaints-to="usenet@i2pn2.org";
posting-account="w/4CleFT0XZ6XfSuRJzIySLIA6ECskkHxKUAYDZM66M";
X-Spam-Checker-Version: SpamAssassin 4.0.0
In-Reply-To: <L2PlxvxSHEVJx+H9A@bongo-ra.co>
 by: D - Tue, 30 Jan 2024 15:38 UTC

On Tue, 30 Jan 2024, Spiros Bousbouras wrote:

> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
> Dan Purgert <dan@djph.net> wrote:
>> On 2024-01-30, Sylvia Else wrote:
>>> This is really a rant - venting to release some of the frustration.
>>>
>>> I'm in the process of selling my house, and I need somewhere secure to
>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>> otherwise bank with, and interact online with it using a live-DVD on a
>>> system that has no storage. So no risk of key loggers or other hacks.
>>> I'd remember the strong password, and not have it written down anywhere.
>>
>> Until you don't remember it, then what?
>>
>> Because let's face it, eventually we all forget the password.
>
> That's a very presumptuous thing to say. I have my own ways of storing and
> retrieving passwords (which may include just my memory) and I'm confident
> they are secure and reliable enough. So don't include me in your "we".
>
> I share Sylvia's frustration and it's not just with banks. Pretty much any
> online site with an option to create an account , will also have some kind
> of password reminder , usually sent to your email. Very often I have wished
> for sites to offer the option when creating an account to disable any
> password reminders but I have yet to see a site which does this.
>

Just for the record, please add me to the "we". When it comes to password
reset, I've never had a bank that does not have go to their office in
person to setup accounts and change passwords.

Re: Using SMS for password reset.

<upb8oq$129vn$2@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3373&group=comp.misc#3373

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!rocksolid2!news.neodome.net!news.mixmin.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: rich@example.invalid (Rich)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 16:39:54 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 58
Message-ID: <upb8oq$129vn$2@dont-email.me>
References: <l1rpu5FbrprU1@mid.individual.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 30 Jan 2024 16:39:54 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="82a4aaea436275606af8d523a90d7c18";
logging-data="1124343"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18lEsIyHodBgVvXE4k/8tYI"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:Jf7qJZyqDjyl19jDhpwgfmnxrqg=
 by: Rich - Tue, 30 Jan 2024 16:39 UTC

Sylvia Else <sylvia@email.invalid> wrote:
> This is really a rant - venting to release some of the frustration.
>
> I'm in the process of selling my house, and I need somewhere secure to
> hold the proceeds. I decided I'd create a account with a bank I don't
> otherwise bank with, and interact online with it using a live-DVD on a
> system that has no storage. So no risk of key loggers or other hacks.
> I'd remember the strong password, and not have it written down anywhere.
>
> Except that the banks insist on having a password reset option,
> validated using an SMS. This undermines my attempts at ensuring that the
> account remains secure.

True in a general security sense.

> I've tried telling banks (and other entities, indeed) that I don't want
> the ability to reset the password. No go, because such an option is not
> implemented in their systems.

Your request is the one odd one in a sea of others that all /rely/ on
the ability to reset passwords, and as banks are, well, /banks/ and not
security researchers, they simply will not understand why you want to
be "so different from everyone" -- and the result is a "can't do that"
answer (because, likely, they really can't do that).

> Telcos in Australia have some quite strict rules regarding transfer of
> mobile phone numbers, but the rules still get broken, and frauds
> committed thereby.

The US /supposedly/ has rules to prevent it as well, but an 'insider'
can always work around the rules, and so it happens here too.

> If someone perpetrated a fraud as a consequence of the SMS password
> reset, I'd have a good case that it was a fraud against the bank, rather
> than against me, and that it was therefore the bank's loss.
>
> Still, I'd rather not have to deal with it.

Agreed.

> I looked at having a SecurIDĀ® device as 2FA. But guess what? It can be
> used to reset the password.
>
> So I'm tearing my hair out. Why do banks have this huge blind-spot when
> it comes to resetting passwords?

Because banks are not "security researchers" and are instead simply
following the "best practices playbook" (which is also not written by
"security researchers" but may be written by "govt. regulators"). And
if the playbook says "provide abililty to reset password with 2FA
security" and a separate chapter lists "SMS" as a valid 2FA method,
then they are "protected" (which in this environment means protected
from a charge of negligence for not following "best practices"). But
they are not in the business of "protecting" you -- they are in the
business of "protecting" themselves from negligence charges. The
amount of "protection" you receive as a secondary result of them
protecting themselves is what you end up seeing as your protection.

Re: Using SMS for password reset.

<87y1c6vkps.fsf@yaxenu.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3374&group=comp.misc#3374

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!rocksolid2!news.neodome.net!news.mixmin.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jshem@yaxenu.org (Julieta Shem)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 13:39:59 -0300
Organization: A noiseless patient Spider
Lines: 32
Message-ID: <87y1c6vkps.fsf@yaxenu.org>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: dont-email.me; posting-host="2ba2658f65e8ec60da22f377592b0172";
logging-data="1130195"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18ldqB9OMFyHC91SGRahuetTN2BYRAgQvI="
Cancel-Lock: sha1:r7Muj2QyyQR58Rmd5leKVAwqJ1w=
sha1:ih8o5r7ujCReuqaYhmwD0psJc3A=
 by: Julieta Shem - Tue, 30 Jan 2024 16:39 UTC

Spiros Bousbouras <spibou@gmail.com> writes:

> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
> Dan Purgert <dan@djph.net> wrote:
>> On 2024-01-30, Sylvia Else wrote:
>> > This is really a rant - venting to release some of the frustration.
>> >
>> > I'm in the process of selling my house, and I need somewhere secure to
>> > hold the proceeds. I decided I'd create a account with a bank I don't
>> > otherwise bank with, and interact online with it using a live-DVD on a
>> > system that has no storage. So no risk of key loggers or other hacks.
>> > I'd remember the strong password, and not have it written down anywhere.
>>
>> Until you don't remember it, then what?
>>
>> Because let's face it, eventually we all forget the password.
>
> That's a very presumptuous thing to say. I have my own ways of storing and
> retrieving passwords (which may include just my memory) and I'm confident
> they are secure and reliable enough. So don't include me in your "we".
>
> I share Sylvia's frustration and it's not just with banks.

I share Sylvia's frustration as well. It's not just with banks. Things
are become ever more centralized. Centralization designs products and
services to the average customer and business invest in shaping people
so that if fits their business model. Along with that new cultural
values appear. People seem a lot less interested in serving people. We
have to fit in with the system now. People who keep their individuality
are nuisance to the system.

I wonder what happens in the limiting case.

Re: Using SMS for password reset.

<65b963eb@news.ausics.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3376&group=comp.misc#3376

  copy link   Newsgroups: comp.misc
Message-ID: <65b963eb@news.ausics.net>
Subject: Re: Using SMS for password reset.
Newsgroups: comp.misc
References: <l1rpu5FbrprU1@mid.individual.net>
User-Agent: tin/2.0.1-20111224 ("Achenvoir") (UNIX) (Linux/2.4.31 (i586))
NNTP-Posting-Host: news.ausics.net
From: newsmaster@ausics.net
Date: 31 Jan 2024 07:02:36 +1000
Organization: Ausics - https://newsgroups.ausics.net
Lines: 56
X-Complaints: abuse@ausics.net
Path: i2pn2.org!i2pn.org!news.bbs.nz!news.ausics.net!not-for-mail
 by: newsmaster@ausics.net - Tue, 30 Jan 2024 21:02 UTC

Sylvia Else <sylvia@email.invalid> wrote:
> This is really a rant - venting to release some of the frustration.
>
> I'm in the process of selling my house, and I need somewhere secure to
> hold the proceeds. I decided I'd create a account with a bank I don't
> otherwise bank with, and interact online with it using a live-DVD on a
> system that has no storage. So no risk of key loggers or other hacks.

Although probably a higher risk of running software that's missing
the latest security bug fixes, and therefore _might_ be vulnerable
to snooping on the encrypted data, or page content in web browsers
via Javascript. I suppose you could run updates each time after
booting though.

> Except that the banks insist on having a password reset option,
> validated using an SMS. This undermines my attempts at ensuring that the
> account remains secure.

Yes the SMS requirement annoys me too, although for different
reasons related to me not frequently using a mobile at all. But I
only have online banking enabled for accounts from which I want to
make payments for online purchases, where I transfer the required
amount into them before-hand. Otherwise money is kept in accounts
that don't have online banking and I don't have to provide a mobile
phone number for them, although I believe it is an option for
verification with phone banking.

> I've tried telling banks (and other entities, indeed) that I don't want
> the ability to reset the password. No go, because such an option is not
> implemented in their systems.
>
> Telcos in Australia have some quite strict rules regarding transfer of
> mobile phone numbers, but the rules still get broken, and frauds
> committed thereby.

I wonder if there's an equivalent to 127.0.0.1 for mobile phone
numbers, where you _know_ they can't call anyone with that number
(even yourself)? CBA requires the SMS code while setting up and
using their online banking funtions too though (rather annoying for
me because I keep my mobile phone in the car all the time).

> If someone perpetrated a fraud as a consequence of the SMS password
> reset, I'd have a good case that it was a fraud against the bank, rather
> than against me, and that it was therefore the bank's loss.
>
> Still, I'd rather not have to deal with it.

Yes I've had bank staff tell me about similar protections
when I say I don't want online banking, but it ignores the
immediate difficulty of finding that all your money's gone and
then having to wait penniless until the bank gets around to looking
into it (and hoping they're competent at doing so).

--
__ __
#_ < |\| |< _# | Note: I won't see posts made from Google Groups |

Re: Using SMS for password reset.

<l1tcggFk5rdU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3377&group=comp.misc#3377

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!paganini.bofh.team!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: sylvia@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 09:45:36 +1100
Lines: 6
Message-ID: <l1tcggFk5rdU1@mid.individual.net>
References: <l1rpu5FbrprU1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net mpX3m33axbei4qwlSYcsfgJKFEe+hhKo1mqb7oHJ0P/4OSKxsN
Cancel-Lock: sha1:aANZmhM59lieI6cE3VDmLc4g78w= sha256:7Aqsh9bdGXXRe261czZy1BAMvph1YdLYctD/C2HqLac=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Content-Language: en-US
In-Reply-To: <l1rpu5FbrprU1@mid.individual.net>
 by: Sylvia Else - Tue, 30 Jan 2024 22:45 UTC

Just as an aside, when I created my online account for the bank, it told
me my user id, expressed as two four digit groups separated by a space.

But will it accept the user id in that format? No, of course not.

Sylvia.

Re: Using SMS for password reset.

<upc1at$16mal$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3378&group=comp.misc#3378

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: rich@example.invalid (Rich)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 23:39:09 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 27
Message-ID: <upc1at$16mal$1@dont-email.me>
References: <l1rpu5FbrprU1@mid.individual.net> <l1tcggFk5rdU1@mid.individual.net>
Injection-Date: Tue, 30 Jan 2024 23:39:09 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="2989444872a065f815d695cd7df518a6";
logging-data="1268053"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/36fm0oYqZwAjnJHe5p7z5"
User-Agent: tin/2.6.1-20211226 ("Convalmore") (Linux/5.15.139 (x86_64))
Cancel-Lock: sha1:eXqYqG2IxKF5ENKxproFy77X6J0=
 by: Rich - Tue, 30 Jan 2024 23:39 UTC

Sylvia Else <sylvia@email.invalid> wrote:
> Just as an aside, when I created my online account for the bank, it
> told me my user id, expressed as two four digit groups separated by a
> space.
>
> But will it accept the user id in that format? No, of course not.

This is far too common.

What it means is developer team 1, possibly at time 1, created the
"onboard a new user account" web pages, while developer team 2, likely
at different time 2, created the actual "log an existing user on" web
pages, and neither team talked or interacted with each other to learn
what the other team had done.

This is the same symptom that gives "password" fields that (if a
description is even privided) says "use any characters except $ and %
for your password" [1] yet when you actually try to use a password with
^ or # you mysteriously discover that # or ^ is also on the "you can't
use that" list, but not mentioned in the visible documentation. And
sometimes discover that the documented $ or % is actually acceptable.

[1] yes, a code smell for a developer that does not know what they are
doing

Re: Using SMS for password reset.

<8734uextmd.fsf@enoch.nodomain.nowhere>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3379&group=comp.misc#3379

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: mds@bogus.nodomain.nowhere (Mike Spencer)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: 30 Jan 2024 19:56:58 -0400
Organization: Bridgewater Institute for Advanced Study - Blacksmith Shop
Lines: 56
Sender: mds@enoch.nodomain.nowhere
Message-ID: <8734uextmd.fsf@enoch.nodomain.nowhere>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net> <L2PlxvxSHEVJx+H9A@bongo-ra.co> <87y1c6vkps.fsf@yaxenu.org>
Injection-Info: dont-email.me; posting-host="ef0e2415f5bb8d4e94cbd3eb82a00eea";
logging-data="1274188"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/dFchAFnUY8ggWVwPTBKWgeolxDLBj0V0="
Cancel-Lock: sha1:IWrDrgNlfP9vKAyU+k6WaOSQbPQ=
X-Newsreader: Gnus v5.7/Emacs 20.7
X-Clacks-Overhead: 4GH GNU Terry Pratchett
 by: Mike Spencer - Tue, 30 Jan 2024 23:56 UTC

Julieta Shem <jshem@yaxenu.org> writes:

> Spiros Bousbouras <spibou@gmail.com> writes:
>
>> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
>> Dan Purgert <dan@djph.net> wrote:
>>> On 2024-01-30, Sylvia Else wrote:
>>>> This is really a rant - venting to release some of the frustration.
>>>>
>>>> I'm in the process of selling my house, and I need somewhere secure to
>>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>>> otherwise bank with, and interact online with it using a live-DVD on a
>>>> system that has no storage. So no risk of key loggers or other hacks.
>>>> I'd remember the strong password, and not have it written down anywhere.
>>>
>>> Until you don't remember it, then what?
>>>
>>> Because let's face it, eventually we all forget the password.
>>
>> That's a very presumptuous thing to say. I have my own ways of storing and
>> retrieving passwords (which may include just my memory) and I'm confident
>> they are secure and reliable enough. So don't include me in your "we".
>>
>> I share Sylvia's frustration and it's not just with banks.
>
> I share Sylvia's frustration as well. It's not just with banks. Things
> are become ever more centralized. Centralization designs products and
> services to the average customer and business invest in shaping people
> so that if fits their business model. Along with that new cultural
> values appear. People seem a lot less interested in serving people. We
> have to fit in with the system now. People who keep their individuality
> are nuisance to the system.

From the POV of finance (see "financialization of everything",
elsewhere) employees, customers, clients and also product, tangible or
otherwise, are externalities.

> I wonder what happens in the limiting case.

The ultimate promise of the computer, from the earliest days that its
development attracted corporate money, was, "Turn it on; money comes
out". Cryptocurrency is the closest we've come to this ideal but it's
not without problems. Morphing everything that everybody does into a
digital transaction, to the internal mechanisms of which no one [1] has
access, gradually expunging other routines for "what everybody does",
appears to be the leading candidate.

[1] Except for the digital priesthood within any given corporation.
Contemporary AI is offering some promise that systems for
extracting money from the biomass will soon be impenetrable
even to them.

--
Mike Spencer Nova Scotia, Canada

Re: Using SMS for password reset.

<l1thfpFf0eoU4@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3380&group=comp.misc#3380

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: news0009@eager.cx (Bob Eager)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: 31 Jan 2024 00:10:33 GMT
Lines: 30
Message-ID: <l1thfpFf0eoU4@mid.individual.net>
References: <l1rpu5FbrprU1@mid.individual.net>
<l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net n2r7jUUEVS1tRsSIAa5qVAjWFdQ6IbzSHkqabVddJBKWjAf4CM
Cancel-Lock: sha1:oaQNAhhMnaHg9jLcO8O/S8haztE= sha256:HgKc987zzh5Rtc1sYjNnAALWv5nEmzXrHV3oB9fCD4g=
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
 by: Bob Eager - Wed, 31 Jan 2024 00:10 UTC

On Tue, 30 Jan 2024 23:39:09 +0000, Rich wrote:

> Sylvia Else <sylvia@email.invalid> wrote:
>> Just as an aside, when I created my online account for the bank, it
>> told me my user id, expressed as two four digit groups separated by a
>> space.
>>
>> But will it accept the user id in that format? No, of course not.
>
> This is far too common.
>
> What it means is developer team 1, possibly at time 1, created the
> "onboard a new user account" web pages, while developer team 2, likely
> at different time 2, created the actual "log an existing user on" web
> pages,
> and neither team talked or interacted with each other to learn what the
> other team had done.

I had a lot of trouble initially with the NHS app. It turned out that the
password I was using was too long. I think it stored the long version, but
truncated the one I typed in when logging in.

--
Using UNIX since v6 (1975)...

Use the BIG mirror service in the UK:
http://www.mirrorservice.org

Re: Using SMS for password reset.

<87o7d2s30v.fsf@yaxenu.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3381&group=comp.misc#3381

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jshem@yaxenu.org (Julieta Shem)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 22:30:24 -0300
Organization: A noiseless patient Spider
Lines: 15
Message-ID: <87o7d2s30v.fsf@yaxenu.org>
References: <l1rpu5FbrprU1@mid.individual.net>
<l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: dont-email.me; posting-host="a6591e681aa78d410acecfdfd502f4f2";
logging-data="1295064"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+IBverJkBKFIzefDepLECtM3yqslCOFZE="
Cancel-Lock: sha1:wHGe67YzZhHLy/XNieYl9cJSvBQ=
sha1:pNa3suedxxtolFFdr25ps/V4JFU=
 by: Julieta Shem - Wed, 31 Jan 2024 01:30 UTC

Rich <rich@example.invalid> writes:

> Sylvia Else <sylvia@email.invalid> wrote:
>> Just as an aside, when I created my online account for the bank, it
>> told me my user id, expressed as two four digit groups separated by a
>> space.
>>
>> But will it accept the user id in that format? No, of course not.
>
> This is far too common.

[...]

Interesting that the richest industry is not actually able to hire a
competent professional.

Re: Using SMS for password reset.

<upc8gm$psu$1@panix2.panix.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3382&group=comp.misc#3382

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!panix!.POSTED.panix2.panix.com!panix2.panix.com!not-for-mail
From: kludge@panix.com (Scott Dorsey)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: 31 Jan 2024 01:41:42 -0000
Organization: Former users of Netcom shell (1989-2000)
Lines: 9
Message-ID: <upc8gm$psu$1@panix2.panix.com>
References: <l1rpu5FbrprU1@mid.individual.net> <l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me> <87o7d2s30v.fsf@yaxenu.org>
Injection-Info: reader1.panix.com; posting-host="panix2.panix.com:166.84.1.2";
logging-data="13968"; mail-complaints-to="abuse@panix.com"
 by: Scott Dorsey - Wed, 31 Jan 2024 01:41 UTC

In article <87o7d2s30v.fsf@yaxenu.org>, Julieta Shem <jshem@yaxenu.org> wrote:
>
>Interesting that the richest industry is not actually able to hire a
>competent professional.

"Rich people did not get rich by spending money."
-- my uncle Paul
--
"C'est un Nagra. C'est suisse, et tres, tres precis."

Re: Using SMS for password reset.

<877cjqs16x.fsf@yaxenu.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3383&group=comp.misc#3383

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!paganini.bofh.team!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jshem@yaxenu.org (Julieta Shem)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 30 Jan 2024 23:09:58 -0300
Organization: A noiseless patient Spider
Lines: 15
Message-ID: <877cjqs16x.fsf@yaxenu.org>
References: <l1rpu5FbrprU1@mid.individual.net>
<l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me>
<87o7d2s30v.fsf@yaxenu.org> <upc8gm$psu$1@panix2.panix.com>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: dont-email.me; posting-host="a6591e681aa78d410acecfdfd502f4f2";
logging-data="1306443"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18e0ZWl8iYXVVqB1f0AXfYurzHPxd5LPKw="
Cancel-Lock: sha1:yiF3Fs4xBjsWet0Ym7kPPcaDCGY=
sha1:v4c7D0CLNPjD1tzQQm/v4nF1uBY=
 by: Julieta Shem - Wed, 31 Jan 2024 02:09 UTC

kludge@panix.com (Scott Dorsey) writes:

> In article <87o7d2s30v.fsf@yaxenu.org>, Julieta Shem <jshem@yaxenu.org> wrote:
>>
>>Interesting that the richest industry is not actually able to hire a
>>competent professional.
>
> "Rich people did not get rich by spending money."
> -- my uncle Paul

I think it's more profound than that. I think (1) the craft is a lot
more difficult than the average professional is able to understand; (2)
not to mention the average entrepeneur who hired the professional; (3) a
rich industry that targets poor people doesn't care: they have numbers
that say that they won't make more money by having some respect.

Re: Using SMS for password reset.

<l1tppqFmtp1U1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3384&group=comp.misc#3384

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: sylvia@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 13:32:26 +1100
Lines: 21
Message-ID: <l1tppqFmtp1U1@mid.individual.net>
References: <l1rpu5FbrprU1@mid.individual.net>
<l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net UJ0aLgcI/A55OQePCFaeiwwiE2QtLoWvwbnPRssgg7eTn2rMmo
Cancel-Lock: sha1:WvmPWXD3uO9Lk1IXh2Gp29/Gn/I= sha256:+BWgZwrGOD61tO3EKBJYkNxJfzhWoqMps/ibIYzD/sg=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Content-Language: en-US
In-Reply-To: <upc1at$16mal$1@dont-email.me>
 by: Sylvia Else - Wed, 31 Jan 2024 02:32 UTC

On 31-Jan-24 10:39 am, Rich wrote:
> Sylvia Else <sylvia@email.invalid> wrote:

> This is the same symptom that gives "password" fields that (if a
> description is even privided) says "use any characters except $ and %
> for your password" [1] yet when you actually try to use a password with
> ^ or # you mysteriously discover that # or ^ is also on the "you can't
> use that" list, but not mentioned in the visible documentation. And
> sometimes discover that the documented $ or % is actually acceptable.
>

I once came across a site that validated the password against a set of
permitted characters at the time of login (why on Earth would it do
that?), and the set of characters was different from the set used to
validate the password when setting it.

So, of course, I'd set a password, and then found it rejected at login
because it contained an unacceptable character.

Sylvia.

Re: Using SMS for password reset.

<0870b687-afd2-5d38-ba64-284cc950fda7@example.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3385&group=comp.misc#3385

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!.POSTED!not-for-mail
From: nospam@example.net (D)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 10:58:34 +0100
Organization: i2pn2 (i2pn.org)
Message-ID: <0870b687-afd2-5d38-ba64-284cc950fda7@example.net>
References: <l1rpu5FbrprU1@mid.individual.net> <l1tcggFk5rdU1@mid.individual.net> <upc1at$16mal$1@dont-email.me> <87o7d2s30v.fsf@yaxenu.org> <upc8gm$psu$1@panix2.panix.com> <877cjqs16x.fsf@yaxenu.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII; format=flowed
Injection-Info: i2pn2.org;
logging-data="1182855"; mail-complaints-to="usenet@i2pn2.org";
posting-account="w/4CleFT0XZ6XfSuRJzIySLIA6ECskkHxKUAYDZM66M";
In-Reply-To: <877cjqs16x.fsf@yaxenu.org>
X-Spam-Checker-Version: SpamAssassin 4.0.0
 by: D - Wed, 31 Jan 2024 09:58 UTC

On Tue, 30 Jan 2024, Julieta Shem wrote:

> kludge@panix.com (Scott Dorsey) writes:
>
>> In article <87o7d2s30v.fsf@yaxenu.org>, Julieta Shem <jshem@yaxenu.org> wrote:
>>>
>>> Interesting that the richest industry is not actually able to hire a
>>> competent professional.
>>
>> "Rich people did not get rich by spending money."
>> -- my uncle Paul
>
> I think it's more profound than that. I think (1) the craft is a lot
> more difficult than the average professional is able to understand; (2)
> not to mention the average entrepeneur who hired the professional; (3) a
> rich industry that targets poor people doesn't care: they have numbers
> that say that they won't make more money by having some respect.
>

It's actually easily explained. There is no market or regulatory pressure.
As long as that does not exist they won't do it.

Also remember that banks are an extension of the government, and therefore
have a massive say in the rules that will govern them. So what they do is
to develop rules and laws that are expensive for newcomers to follow but
easy for them.

Newcomers who design their solutions from scratch will have higher
security. Therefore there is no law that demands this since it would be
very costly for legacy banks.

Re: Using SMS for password reset.

<slrnurkaop.2h7.dan@djph.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3386&group=comp.misc#3386

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dan@djph.net (Dan Purgert)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 11:10:34 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 35
Message-ID: <slrnurkaop.2h7.dan@djph.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co>
Injection-Date: Wed, 31 Jan 2024 11:10:34 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="7915f359c2e226a186e27c159c7f52db";
logging-data="1574256"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18ezPsZpVB9cVt29FHZc+ngUA7M4Ev+9p8="
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:leoZnbS127YZzEyBQRour7lPook=
 by: Dan Purgert - Wed, 31 Jan 2024 11:10 UTC

On 2024-01-30, Spiros Bousbouras wrote:
> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
> Dan Purgert <dan@djph.net> wrote:
>> On 2024-01-30, Sylvia Else wrote:
>> > This is really a rant - venting to release some of the frustration.
>> >
>> > I'm in the process of selling my house, and I need somewhere secure to
>> > hold the proceeds. I decided I'd create a account with a bank I don't
>> > otherwise bank with, and interact online with it using a live-DVD on a
>> > system that has no storage. So no risk of key loggers or other hacks.
>> > I'd remember the strong password, and not have it written down anywhere.
>>
>> Until you don't remember it, then what?
>>
>> Because let's face it, eventually we all forget the password.
>
> That's a very presumptuous thing to say. I have my own ways of storing and
> retrieving passwords (which may include just my memory) and I'm confident
> they are secure and reliable enough. So don't include me in your "we".

So if I was to sit you down at any freshly installed PC of your choice,
you could log-in to *any* random service to which you have a
username/password combination *from memory* ?

Because if there is even a single service to which the truthful answer
(which, admittedly I will never know; because this is Usenet, and you
can vehemently deny it to your last post) is "well, actually, I'd
have to use [password-tool-of-choice] for that site"; then you are
solidly in the group of "people who have forgotten the password".

--
|_|O|_|
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1 E067 6D65 70E5 4CE7 2860

Re: Using SMS for password reset.

<l1upj2FrqdkU1@mid.individual.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3387&group=comp.misc#3387

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: sylvia@email.invalid (Sylvia Else)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 22:34:58 +1100
Lines: 41
Message-ID: <l1upj2FrqdkU1@mid.individual.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co> <slrnurkaop.2h7.dan@djph.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net KPuVCHcsQZJqS3P3clVYmASwfWV4ALLH3gkZ9Cad1WlsdmYBCQ
Cancel-Lock: sha1:FVkNYMUqwpMkmHR+VT0ZNdPVZ7o= sha256:sq02mcVR32hCL0QHQJEpI0CYC6VMZ397hzySXZysUc4=
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.15.1
Content-Language: en-US
In-Reply-To: <slrnurkaop.2h7.dan@djph.net>
 by: Sylvia Else - Wed, 31 Jan 2024 11:34 UTC

On 31-Jan-24 10:10 pm, Dan Purgert wrote:
> On 2024-01-30, Spiros Bousbouras wrote:
>> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
>> Dan Purgert <dan@djph.net> wrote:
>>> On 2024-01-30, Sylvia Else wrote:
>>>> This is really a rant - venting to release some of the frustration.
>>>>
>>>> I'm in the process of selling my house, and I need somewhere secure to
>>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>>> otherwise bank with, and interact online with it using a live-DVD on a
>>>> system that has no storage. So no risk of key loggers or other hacks.
>>>> I'd remember the strong password, and not have it written down anywhere.
>>>
>>> Until you don't remember it, then what?
>>>
>>> Because let's face it, eventually we all forget the password.
>>
>> That's a very presumptuous thing to say. I have my own ways of storing and
>> retrieving passwords (which may include just my memory) and I'm confident
>> they are secure and reliable enough. So don't include me in your "we".
>
> So if I was to sit you down at any freshly installed PC of your choice,
> you could log-in to *any* random service to which you have a
> username/password combination *from memory* ?
>
> Because if there is even a single service to which the truthful answer
> (which, admittedly I will never know; because this is Usenet, and you
> can vehemently deny it to your last post) is "well, actually, I'd
> have to use [password-tool-of-choice] for that site"; then you are
> solidly in the group of "people who have forgotten the password".
>
>
Just need to remember the one username and password for site where the
backup copy of the encrypted password database is stored, and the
passphrase to decrypt that database. Not that hard.

Sylvia.

Re: Using SMS for password reset.

<UKRnzwK2I7OBPZijg@bongo-ra.co>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3388&group=comp.misc#3388

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.neodome.net!news.mixmin.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: spibou@gmail.com (Spiros Bousbouras)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 12:06:09 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 60
Message-ID: <UKRnzwK2I7OBPZijg@bongo-ra.co>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net> <L2PlxvxSHEVJx+H9A@bongo-ra.co>
<slrnurkaop.2h7.dan@djph.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 31 Jan 2024 12:06:09 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="71f587f50824bad52c64b49f3a9b24de";
logging-data="1590646"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18AHqDt3i8HLfqyaaLtHa0E"
Cancel-Lock: sha1:8w+mtxjhi/2u4Z2f26xgibPIIys=
X-Server-Commands: nowebcancel
In-Reply-To: <slrnurkaop.2h7.dan@djph.net>
X-Organisation: Weyland-Yutani
 by: Spiros Bousbouras - Wed, 31 Jan 2024 12:06 UTC

On Wed, 31 Jan 2024 11:10:34 -0000 (UTC)
Dan Purgert <dan@djph.net> wrote:
> On 2024-01-30, Spiros Bousbouras wrote:
> > On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
> > Dan Purgert <dan@djph.net> wrote:
> >> On 2024-01-30, Sylvia Else wrote:
> >> > This is really a rant - venting to release some of the frustration.
> >> >
> >> > I'm in the process of selling my house, and I need somewhere secure to
> >> > hold the proceeds. I decided I'd create a account with a bank I don't
> >> > otherwise bank with, and interact online with it using a live-DVD on a
> >> > system that has no storage. So no risk of key loggers or other hacks.
> >> > I'd remember the strong password, and not have it written down anywhere.
> >>
> >> Until you don't remember it, then what?
> >>
> >> Because let's face it, eventually we all forget the password.
> >
> > That's a very presumptuous thing to say. I have my own ways of storing and
> > retrieving passwords (which may include just my memory) and I'm confident
> > they are secure and reliable enough. So don't include me in your "we".
>
> So if I was to sit you down at any freshly installed PC of your choice,
> you could log-in to *any* random service to which you have a
> username/password combination *from memory* ?

No. I will note in passing that even a yes answer would not necessarily
be unrealistic. It depends on how many online accounts one has. Someone
may only have an email online account and nothing more so would only
need to remember one password.

> Because if there is even a single service to which the truthful answer
> (which, admittedly I will never know; because this is Usenet, and you
> can vehemently deny it to your last post) is "well, actually, I'd
> have to use [password-tool-of-choice] for that site"; then you are
> solidly in the group of "people who have forgotten the password".

No , I am in the group of people who never memorised the password. I have
sites for which I have memorised a password and for those I don't worry
about forgetting it (unless I go senile but then I may forget many more
things so it becomes a more general problem). And I have sites for which
I made no effort to memorise the password and I have other ways of retrieving
it. And I also have sites for which I made a decision that I wasn't going to
use them again and eventually forgot the password. But I considered those
examples irrelevant to the discussion.

But my main point was that I do not want any help from the site in retrieving
forgotten or lost passwords because I often find that the method offered
reduces security and I resent the fact that sites do not offer the
possibility to turn off such methods.

In any case , I see now that I read in your post more than what you intended.
You said "then what?" and I interpreted that as suggesting that we all need
help from the website in retrieving passwords and that's what I found
especially presumptuous.

--
I am writing this mail to you with serious tears in my eyes and great
sorrow in my heart
An email offering me 30% of $7,200,200

Re: Using SMS for password reset.

<87o7d1ql0a.fsf@yaxenu.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3389&group=comp.misc#3389

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jshem@yaxenu.org (Julieta Shem)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Wed, 31 Jan 2024 17:57:09 -0300
Organization: A noiseless patient Spider
Lines: 58
Message-ID: <87o7d1ql0a.fsf@yaxenu.org>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co> <87y1c6vkps.fsf@yaxenu.org>
<8734uextmd.fsf@enoch.nodomain.nowhere>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: dont-email.me; posting-host="a6591e681aa78d410acecfdfd502f4f2";
logging-data="1780974"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18odSba5HU4y/ewji5Yf/q5cz1b1w7EOZo="
Cancel-Lock: sha1:KHl8pszFaXiwOYTbFs11+vU3aIs=
sha1:Fu5OL7XZc+u96zrVEMwb/uadLSc=
 by: Julieta Shem - Wed, 31 Jan 2024 20:57 UTC

Mike Spencer <mds@bogus.nodomain.nowhere> writes:

> Julieta Shem <jshem@yaxenu.org> writes:
>
>> Spiros Bousbouras <spibou@gmail.com> writes:
>>
>>> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
>>> Dan Purgert <dan@djph.net> wrote:
>>>> On 2024-01-30, Sylvia Else wrote:
>>>>> This is really a rant - venting to release some of the frustration.
>>>>>
>>>>> I'm in the process of selling my house, and I need somewhere secure to
>>>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>>>> otherwise bank with, and interact online with it using a live-DVD on a
>>>>> system that has no storage. So no risk of key loggers or other hacks.
>>>>> I'd remember the strong password, and not have it written down anywhere.
>>>>
>>>> Until you don't remember it, then what?
>>>>
>>>> Because let's face it, eventually we all forget the password.
>>>
>>> That's a very presumptuous thing to say. I have my own ways of storing and
>>> retrieving passwords (which may include just my memory) and I'm confident
>>> they are secure and reliable enough. So don't include me in your "we".
>>>
>>> I share Sylvia's frustration and it's not just with banks.
>>
>> I share Sylvia's frustration as well. It's not just with banks. Things
>> are become ever more centralized. Centralization designs products and
>> services to the average customer and business invest in shaping people
>> so that if fits their business model. Along with that new cultural
>> values appear. People seem a lot less interested in serving people. We
>> have to fit in with the system now. People who keep their individuality
>> are nuisance to the system.
>
> From the POV of finance (see "financialization of everything",
> elsewhere) employees, customers, clients and also product, tangible or
> otherwise, are externalities.

That's a paragraph to the expert. I had to read on ``financialization
of everything'' and get a definition of externality. But, okay, I
understand the connection now. If customers and products are
externalities, then I think we are in agreement---businesses are not
really interested in what they're doing, which explains why so many of
them try various things until they finally ``succeeed''. It doesn't
really matter how they get there.

>> I wonder what happens in the limiting case.
>
> The ultimate promise of the computer, from the earliest days that its
> development attracted corporate money, was, "Turn it on; money comes
> out". Cryptocurrency is the closest we've come to this ideal but it's
> not without problems. Morphing everything that everybody does into a
> digital transaction, to the internal mechanisms of which no one [1] has
> access, gradually expunging other routines for "what everybody does",
> appears to be the leading candidate.

You might be quite right.

Re: Using SMS for password reset.

<slrnurndhi.2h7.dan@djph.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3390&group=comp.misc#3390

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.furie.org.uk!usenet.goja.nl.eu.org!weretis.net!feeder8.news.weretis.net!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dan@djph.net (Dan Purgert)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Thu, 1 Feb 2024 15:16:19 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 45
Message-ID: <slrnurndhi.2h7.dan@djph.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co> <slrnurkaop.2h7.dan@djph.net>
<l1upj2FrqdkU1@mid.individual.net>
Injection-Date: Thu, 1 Feb 2024 15:16:19 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="a7a2037e3773f14749fe4ec2cced6908";
logging-data="2236081"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+F3BP7tI0zfg4MtkQVRqlwB9ZJ2KT7BsY="
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:BXh1v1sIuyqz6d9h9jFTnGpmrYg=
 by: Dan Purgert - Thu, 1 Feb 2024 15:16 UTC

On 2024-01-31, Sylvia Else wrote:
> On 31-Jan-24 10:10 pm, Dan Purgert wrote:
>> On 2024-01-30, Spiros Bousbouras wrote:
>>> On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
>>> Dan Purgert <dan@djph.net> wrote:
>>>> On 2024-01-30, Sylvia Else wrote:
>>>>> This is really a rant - venting to release some of the frustration.
>>>>>
>>>>> I'm in the process of selling my house, and I need somewhere secure to
>>>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>>>> otherwise bank with, and interact online with it using a live-DVD on a
>>>>> system that has no storage. So no risk of key loggers or other hacks.
>>>>> I'd remember the strong password, and not have it written down anywhere.
>>>>
>>>> Until you don't remember it, then what?
>>>>
>>>> Because let's face it, eventually we all forget the password.
>>>
>>> That's a very presumptuous thing to say. I have my own ways of storing and
>>> retrieving passwords (which may include just my memory) and I'm confident
>>> they are secure and reliable enough. So don't include me in your "we".
>>
>> So if I was to sit you down at any freshly installed PC of your choice,
>> you could log-in to *any* random service to which you have a
>> username/password combination *from memory* ?
>>
>> Because if there is even a single service to which the truthful answer
>> (which, admittedly I will never know; because this is Usenet, and you
>> can vehemently deny it to your last post) is "well, actually, I'd
>> have to use [password-tool-of-choice] for that site"; then you are
>> solidly in the group of "people who have forgotten the password".
>>
>>
> Just need to remember the one username and password for site where the
> backup copy of the encrypted password database is stored, and the
> passphrase to decrypt that database. Not that hard.

You might want to re-read what was written.

--
|_|O|_|
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1 E067 6D65 70E5 4CE7 2860

Re: Using SMS for password reset.

<slrnurnfea.2h7.dan@djph.net>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3391&group=comp.misc#3391

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: dan@djph.net (Dan Purgert)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Thu, 1 Feb 2024 15:48:43 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 66
Message-ID: <slrnurnfea.2h7.dan@djph.net>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<L2PlxvxSHEVJx+H9A@bongo-ra.co> <slrnurkaop.2h7.dan@djph.net>
<UKRnzwK2I7OBPZijg@bongo-ra.co>
Injection-Date: Thu, 1 Feb 2024 15:48:43 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="a7a2037e3773f14749fe4ec2cced6908";
logging-data="2247430"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/uJ6ref9OWdtNO15Im2/l8ZuSbAnR8Aqc="
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:HJjeWUCPlGRtK1R4xEmWigTaRXE=
 by: Dan Purgert - Thu, 1 Feb 2024 15:48 UTC

On 2024-01-31, Spiros Bousbouras wrote:
> On Wed, 31 Jan 2024 11:10:34 -0000 (UTC)
> Dan Purgert <dan@djph.net> wrote:
>> On 2024-01-30, Spiros Bousbouras wrote:
>> > On Tue, 30 Jan 2024 10:39:28 -0000 (UTC)
>> > Dan Purgert <dan@djph.net> wrote:
>> >> On 2024-01-30, Sylvia Else wrote:
>> >> > This is really a rant - venting to release some of the frustration.
>> >> >
>> >> > I'm in the process of selling my house, and I need somewhere secure to
>> >> > hold the proceeds. I decided I'd create a account with a bank I don't
>> >> > otherwise bank with, and interact online with it using a live-DVD on a
>> >> > system that has no storage. So no risk of key loggers or other hacks.
>> >> > I'd remember the strong password, and not have it written down anywhere.
>> >>
>> >> Until you don't remember it, then what?
>> >>
>> >> Because let's face it, eventually we all forget the password.
>> >
>> > That's a very presumptuous thing to say. I have my own ways of storing and
>> > retrieving passwords (which may include just my memory) and I'm confident
>> > they are secure and reliable enough. So don't include me in your "we".
>>
>> So if I was to sit you down at any freshly installed PC of your choice,
>> you could log-in to *any* random service to which you have a
>> username/password combination *from memory* ?
>
> No. I will note in passing that even a yes answer would not necessarily
> be unrealistic. It depends on how many online accounts one has. Someone
> may only have an email online account and nothing more so would only
> need to remember one password.
>
>> Because if there is even a single service to which the truthful answer
>> (which, admittedly I will never know; because this is Usenet, and you
>> can vehemently deny it to your last post) is "well, actually, I'd
>> have to use [password-tool-of-choice] for that site"; then you are
>> solidly in the group of "people who have forgotten the password".
>
> No , I am in the group of people who never memorised the password.
> [...]
> In any case , I see now that I read in your post more than what you
> intended. You said "then what?" and I interpreted that as suggesting
> that we all need help from the website in retrieving passwords and
> that's what I found especially presumptuous.

I actually figured you were taking issue with the second line; since
it's the more explicit/direct statement that "everyone forgets the
password".

For a bank or other "very public institution that is generally very easy
to access", I can completely agree that "look, if/when you forget your
web-access password, come to the nearest branch" is (probably) a better
solution than a "forgot password" link and answering a couple of
questions about my dog.

But then, what about services that aren't "very public institutions that
are generally very easy to access" (Netflix / Amazon / Google / CC
Company / etc.)?

What would a viable "general" solution be? Call them? Email? Too bad,
create a new account?

--
|_|O|_|
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: DDAB 23FB 19FA 7D85 1CC1 E067 6D65 70E5 4CE7 2860

Re: Using SMS for password reset.

<qOL3gzzw0FzYeF3s=@bongo-ra.co>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3392&group=comp.misc#3392

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: spibou@gmail.com (Spiros Bousbouras)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Thu, 1 Feb 2024 17:57:16 -0000 (UTC)
Organization: To protect and to server
Message-ID: <qOL3gzzw0FzYeF3s=@bongo-ra.co>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net> <L2PlxvxSHEVJx+H9A@bongo-ra.co>
<slrnurkaop.2h7.dan@djph.net> <UKRnzwK2I7OBPZijg@bongo-ra.co> <slrnurnfea.2h7.dan@djph.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Thu, 1 Feb 2024 17:57:16 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="857731"; posting-host="9H7U5kayiTdk7VIdYU44Rw.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="9dIQLXBM7WM9KzA+yjdR4A";
Cancel-Lock: sha256:8Dd6HqM5AKWEmAPArDML+r4AU652sid01ohweh35h/o=
X-Organisation: Weyland-Yutani
X-Notice: Filtered by postfilter v. 0.9.3
X-Server-Commands: nowebcancel
 by: Spiros Bousbouras - Thu, 1 Feb 2024 17:57 UTC

On Thu, 1 Feb 2024 15:48:43 -0000 (UTC)
Dan Purgert <dan@djph.net> wrote:
> On 2024-01-31, Spiros Bousbouras wrote:
> > No , I am in the group of people who never memorised the password.
> > [...]
> > In any case , I see now that I read in your post more than what you
> > intended. You said "then what?" and I interpreted that as suggesting
> > that we all need help from the website in retrieving passwords and
> > that's what I found especially presumptuous.
>
> I actually figured you were taking issue with the second line; since
> it's the more explicit/direct statement that "everyone forgets the
> password".
>
> For a bank or other "very public institution that is generally very easy
> to access", I can completely agree that "look, if/when you forget your
> web-access password, come to the nearest branch" is (probably) a better
> solution than a "forgot password" link and answering a couple of
> questions about my dog.

Yes , as long as the reminder option is safe enough (like personally go to
a building with ID) , I have no problem with it.

> But then, what about services that aren't "very public institutions that
> are generally very easy to access" (Netflix / Amazon / Google / CC
> Company / etc.)?
>
> What would a viable "general" solution be? Call them? Email? Too bad,
> create a new account?

I have already indicated that in <L2PlxvxSHEVJx+H9A@bongo-ra.co> : "Very
often I have wished for sites to offer the option when creating an account to
disable any password reminders" .So when logged in , one would have access to
an account boolean setting which would be enable/disable password reminders.
If the user chooses "disable" and then forgets (or loses or whatever) their
password then that's it , they are locked out of their account forever and
ever. The site would offer appropriate warnings to that effect but ultimately
the user should have the option to disable reminders. If the user decides to
enable them , I don't have a view which would be the best method and I
haven't given it much thought because I would always choose to disable them.
(In a similar vein , I always choose for the site *not* to store credit card
information. How faithfully they implement this , I have no way of knowing)

--
Every theatre is an insane asylum, but an opera theatre is the
ward for the incurables.
Franz Schalk

Re: Using SMS for password reset.

<21fdd84d-2c6d-4a18-baa5-6d749e4ea0c4@scorecrow.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=3416&group=comp.misc#3416

  copy link   Newsgroups: comp.misc
Path: i2pn2.org!i2pn.org!news.swapon.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: 07.013@scorecrow.com (Bruce Horrocks)
Newsgroups: comp.misc
Subject: Re: Using SMS for password reset.
Date: Tue, 6 Feb 2024 23:47:35 +0000
Lines: 48
Message-ID: <21fdd84d-2c6d-4a18-baa5-6d749e4ea0c4@scorecrow.com>
References: <l1rpu5FbrprU1@mid.individual.net> <slrnurhkif.2h7.dan@djph.net>
<l1s2vuFbs14U1@mid.individual.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Trace: individual.net Gbo01RSNSoRubV1FoUfzxAW+GDAkDI7DgFKuQe4iyZl6L/wtKa
Cancel-Lock: sha1:F+tHkBxBBeG7HJyt9d50zArVTos= sha256:pHCi/FVqLopToSBShmqlu5T3En4hFZWk+o69Bhb6GHY=
User-Agent: Mozilla Thunderbird
Content-Language: en-GB
In-Reply-To: <l1s2vuFbs14U1@mid.individual.net>
 by: Bruce Horrocks - Tue, 6 Feb 2024 23:47 UTC

On 30/01/2024 10:57, Sylvia Else wrote:
> On 30-Jan-24 9:39 pm, Dan Purgert wrote:
>> On 2024-01-30, Sylvia Else wrote:
>>> This is really a rant - venting to release some of the frustration.
>>>
>>> I'm in the process of selling my house, and I need somewhere secure to
>>> hold the proceeds. I decided I'd create a account with a bank I don't
>>> otherwise bank with, and interact online with it using a live-DVD on a
>>> system that has no storage. So no risk of key loggers or other hacks.
>>> I'd remember the strong password, and not have it written down anywhere.
>>
>> Until you don't remember it, then what?
>>
>> Because let's face it, eventually we all forget the password.
>>
>
> If I say I won't forget, you've no real reason to doubt me. There are
> many things that I've remembered for decades.

I don't doubt you, but your ability to remember a password that isn't
easily guessable and isn't re-used on multiple sites puts you in the top
0.1% of the population. Banks, however, have to deal with the remaining
99.9% as well.

> In the event that I really did forget, then I'd have to show up at one
> of the bank's offices with physical identity documents.

That's the last thing they want people doing. Imagine going into the
bank to find that there are 15 people ahead of you in the queue, all
waiting to go through a 5 minute process of showing documents to prove
their identity to get their password changed.

The banks don't want to pay their staff to change passwords, they want
to pay them to sell you a new savings account or to take out a loan.

FWIW my bank in the UK gives out a free card reader device, a bit like a
pocket calculator, for their 2FA system. To use it you insert your bank
card, enter your card pin, which it validates using the chip in the chip
& pin card and then displays an 8 digit number to enter into the website.

You use this to log in initially (so no password to remember) and then
to re-authenticate prior to carrying out any sensitive actions such as
making a payment or changing personal details.

--
Bruce Horrocks
Surrey, England

Pages:12
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor