/srv/irclogs.ubuntu.com/2013/05/23/#ubuntu-nz.txt

hadsSo someone sent me an email saying there is a security issue with my website which emails you a termporary password. "I keep my email account open 24/7 on my cellphone, so if someone had stolen my phone they would have access to the account."20:33
hadsmorning20:33
thumpermorning21:05
mwhudsonmorning21:27
Ghads: then I think that guy has bigger problems, like with just about every other website he uses :P21:44
Gmorning21:44
hadsIndeed, I tried to be polite about it.21:45
mwhudsonyou should suggest he uses his phone as a 2fa device21:56
ojwbmorning22:36
ojwbhads: boggle22:36
ojwbthe assumption that email is a secure way to reset a website password is problematic, but it's pretty much ubiquitous22:37
ojwbthe sites I really have a problem with are those which send you back your password itself22:39
ojwblike mailman, which insists on doing that monthly22:39
hadsYeah, these are all salted hashed so a temporary short lived plain text one is generated.22:40
ojwbyeah, that's arguably current best practice22:40
ojwbis this for nicegear?  presumably that would allow them to see things like his previous orders, which you presumably also emailed to him...22:41
hadsYeah22:42
hadsNevermind the rest of the things on the phone.22:42
ajmitchor being able to reset any other account out there that doesn't use 2fa (though the 2nd factor is probably on the phone)22:42
ojwbthere's a bank ad currently which touts being able to send payments to your facebook friends22:44
ojwbso there's now a clear monetary incentive for scammers to get you to friend them on facebook22:45
ojwbsome days i think I'm just getting old and cranky, other days the world seems to have lost the plot22:46
ojwblike credit cards you just need to wave at the till to pay with...22:47
Gojwb: the ASB one?22:52
chiltsmorning22:52
ojwbG: maybe - it has Brian Blessed in22:52
Gthat is actually what I like about Westpac's mobile platform, they have a 'Cashtank' app, it does one thing, and one thing only, and that is show me how much money is in my main account, it can't do anything else - lose my phone no biggy on that department, my money is safe22:53
* ajmitch feels like such a luddite without a modern phone22:53
chiltsG: "NO BIGGY!    YEEE BIGGIE!!!!"22:53
chilts+S22:54
chiltsdamn22:54
* chilts likes Brian Blessed22:54
Gchilts: well they'd still be able to read my e-mail, but the main thing is that my savings are safe because there is no way to get from the cashtank app to any other banking function (unless Westpac has a pretty big hole in their API)22:55
chiltsyeah, sounds like a good app that Cashtank one22:55
chiltsI was merely commenting on the ASB adverts :)22:55
chilts(the one where the farmer saves the sheep and says "no biggie"22:56
chiltsI'd prolly install something like that, ie. a read-only interface to my accounts22:56
Goh right, I skip the ASB ads, they bug me22:56
chiltsheh22:56
chiltsthey used to for me, but this series is ok22:57
chiltson the other hand, I moved away from ASB 'coz they were crap22:57
chiltsfor not as bad as ANZ22:57
chiltss/for/but/22:57
chiltsinteresting typo22:57
GWestpac does some pretty silly things, they appear to be more spammy than any other bank (in terms of marketing/offers with statements/credit card bills etc)22:58
Gmy favourite is I get e-mails from a Branch Manager, i've only ever visited his branch once22:59
ojwbprobably lonely23:02
Gyeah, I kinda wish there was a mainstream bank that just didn't suck (they are all sell-outs)23:04

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!