All Posts by Date or last 15, 30, 90 or 180 days.
also by Lloyd: diglloyd.com photography and WindInMyFace.com
Thank you for purchasing through links and ads on this site.
OWC / MacSales.com...
diglloyd Deal Finder...
Buy other stuff at Amazon.com...
Get up to 16x more storage and 2x the speeds of the original drive
Handpicked deals...
$1799 $1399
SAVE $400

$719 $230
SAVE $489

$198 $138
SAVE $60

$695 $195
SAVE $500

$1997 $897
SAVE $1100

$1099 $999
SAVE $100

$348 $278
SAVE $70

$348 $278
SAVE $70

$3099 $2499
SAVE $600

$2099 $1799
SAVE $300

$275 $275
SAVE $0

$699 $499
SAVE $200

$1699 $1299
SAVE $400

$2999 $2999
SAVE $0

$1699 $1443
SAVE $256

$2798 $2498
SAVE $300

$2399 $2249
SAVE $150

$3798 $1898
SAVE $1900

$2798 $2498
SAVE $300

$2497 $1997
SAVE $500

$2498 $1798
SAVE $700

$3297 $2197
SAVE $1100

$2798 $2498
SAVE $300

$2998 $2498
SAVE $500

$1398 $1198
SAVE $200

$898 $798
SAVE $100

$400 $250
SAVE $150

$1299 $939
SAVE $360

$4078 $4078
SAVE $0

$4499 $2999
SAVE $1500

$4999 $4599
SAVE $400

$2199 $1999
SAVE $200

$2799 $2349
SAVE $450

$3099 $2499
SAVE $600

$2001 $1298
SAVE $703

$249 $149
SAVE $100

$2844 $2297
SAVE $547

$1199 $1099
SAVE $100

$2019 $1399
SAVE $620

$999 $949
SAVE $50

A Pseudo-Security Trend: Password Reset and Locked Accounts

Last Friday, I was locked out of one of my email accounts by the provider because of “too many failed login attempts”.

None of which I made—it was someone trying to hack my account. I was told that this is a new “security feature”. But I have a good password, and I don’t want to be locked out of my account at any time.

In my case, I had to wait all weekend for a password reset, since this particular organization was closed on weekends. This pretty much makes this email provider useless for anything but trivial stuff; the account could be locked at any time.

What such security features really do is to play into the hands of hackers, allowing trivially easy denial of service attacks. Denial of service attacks are typically in the context of web sites (overwhelming a site), but can be applied to email or any kind of login account on a web site. For example:

  1. Dig up 100 million email addresses (many ways to do this).
  2. Fake login attempts N+1 times, where N is the cutoff for locking the account. Starting Friday night of course, so customer support staff are thinned out.
  3. Sit back and laugh as 100 million users find themselves locked out of their email, if only for a day or two.
  4. Repeat each day (hey, bot nets are cheap).

Variations include targeting specific providers. Web sites that lock accounts this way are in essence implementing denial of service support for hackers.

There are many other ways to approach this, other than this crude bludgeon. For starters, allowing the user to decline this behavior (perhaps requiring an especially strong password), an option to notify a user about activity, additional prompts if a login occurs after failures, two factor authentication including apps like Authy, etc.

Corollary — nuisance messsages from “password reset” dialogs

Apple provides an iForgot.apple.com site to reset a password. It’s an ongoing headache for me, since Apple kicks me over there if I type my password wrong just twice (which I do sometimes do if my hands are stiff and cold). Very annoying behavior. But 1Password eliminates that issue for me now. Except not in iTunes or the AppStore, where 1Password doesn’t apply. So it still gets me on a regular basis.

That is relatively minor. The bigger headache is the regular recept of this message below, which is some hacker-generated thing (not me). And sometimes this is followed or preceded by an Apple “account locked” email, similar to that discussed above. Ditto for my Apple Developer account, which generally locks me out every month or so.

Nuisance email

2-factor authentication

Apple has a 2-step authentication approach for purchases, but it’s unclear if it has been applied the idea to the above nuisance factors. Now enabled, MPG will soon see.

Apple 2-step verification security enabled

Save the tax, we pay you back, instantly!
View all handpicked deals...

Dell UltraSharp 27 U2717D 27" 16:9 InfinityEdge IPS Monitor
$719 $230
SAVE $489

diglloyd.com | Terms of Use | PRIVACY POLICY
Contact | About Lloyd Chambers | Consulting | Photo Tours
Mailing Lists | RSS Feeds | Twitter
Copyright © 2019 diglloyd Inc, all rights reserved.
Display info: __RETINA_INFO_STATUS__