Skip to main content

This kind of thing happens too often, I'm sure.

I ran into an issue with a service that I was using earlier today.  I won't mention any names to protect the (not so) innocent, but it struck me as a pretty big security problem.

I needed to access the service's website, but I forgot the password that I used when I signed up.  Unfortunately I was with another company when I created my account, so I no longer had access to the email address I used when I created the account.  I sent them a polite message (very slightly paraphrased):

I'm trying to get access to my account. I changed jobs over the summer and no longer can access the email address myemail@somewhere.com but I'm hoping I can change the address. Thanks! 

I expected to have to call in, verify some security information, tell them something, ANYTHING to prove that I was who I said I was.  Instead, I got the following reply (to a different email address) only 92 minutes later (again, slightly paraphrased):

I am sorry to hear you are encountering issues accessing your account.  Please use the following link to provide a new password for your account.

https://a.url.where.i.can.easily.reset.my.password.with.no.further.verification.com

Once you are logged in go to "my account" and change the email address listed in your profile.

Maybe I'm reading too much into this... but in 2013, shouldn't we have better security than this?  I literally could have been ANYONE sending this message.  Fortunately there are no credit card details saved in my account, but I think this was too easy.

Do you think I'm overreacting here, or do you think companies have more of an obligation to determine identity in this situation?  Please share your comments below.

Comments

  1. In case it wasn't obvious, the URL they provided gave me the ability to reset my password; I then had full access to the account.

    ReplyDelete
  2. There is no tool more powerful in the modern day for bypassing the strongest of encryption methods and the most stringent security measures than simple social engineering. This same technique when applied maliciously can be used to obtain banking details, email accounts, or worse Until we can remove the human element from security procedures, they will always be as vulnerable as the weakest willed employee involved.

    ReplyDelete

Post a Comment

Popular posts from this blog

The Gobbler from Arby's

Stop.  Stop what you're doing and go to Arby's. Right. Now.  Have them make you a Gobbler .  This is not something you'll regret. Go. Eat this thing. Look at that bacon. Go. Arby's has a new sandwich.  It's called "The Gobbler" and as far as I can tell it's two things: a vehicle for their new deep fried turkey, and an attempt at a Thanksgiving themed sandwich.  It's also a third thing: magically delicious. move over Lucky, there's a new holiday mascot on the block Unwrapping: this actually looks like a sandwich.  It looks appetizing.  It looks like something I want to eat.  It doesn't look like the promo photo above, but it doesn't look like someone was flailing around and accidentally smashed up a sandwich, either. sexy Instagram caption goes here First bite: Wow.  I mean, "WOW."  Holy h*ck this is good.  The turkey has a really bold, meaty flavor.  It tastes a lot like turkey sliced fresh from your...

Sheetz Sandwich Standoff: El Gringo vs Twisted Swiss

My wife left me alone for dinner tonight so I decided to check out the latest GetGo offerings... but to my great chagrin, they have no promotional subs. My travels led me to the local Sheetz, where I'd be able to keep eating the best gas station sandwiches around. To keep tradition alive, I picked the two most outrageous "Burgerz" on the menu: El Gringo and Twisted Swiss. The ingredient list is promising: Twisted Swiss is the burger with topped with swiss cheese, cole slaw, pickles, bacon, and whatever "Boom Boom Sauce" is on a pretzel bun.  El Gringo is the burger topped with pepper jack cheese, chili, Doritos, and BBQ sauce on a regular old bun. I unwrapped them both and stood back to admire the majesty before me. They're not pretty, but they do look a lot better out of the wrapper than many fast food burgers I've eaten. Twisted Swiss I expected this sandwich to be an awful mess.  It just seemed like a bunch ...

Interviewing: Tell Stories

Softball questions  are questions the interviewer asks to try to find out about your personality, your history, your level of enthusiasm, and your experience.  While technical questions evaluate your skills or your knowledge, softball questions are meant to have you talk about less quantifiable abilities.  An interviewer might ask a dozen or more softball questions to determine what you're like outside of an interview room. The word to remember for interviews, especially the softball questions, is: STORIES .  People who are good storytellers tend to be good interviewees. Technical questions are important - you need the skills to be able to do the job.  However, often interviewers are convinced by your answers to softball questions - then they spend the rest of the interview trying to convince themselves why they should hire you, instead of spending the rest of the interview trying to convince themselves why they shouldn't. A great strategy for prepa...