Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 34

Thread: Two factor authentication - have you? Passwords

  1. #21
    NavyDiver's Avatar
    NavyDiver is offline Very Very Lucky! Gold Subscriber
    Join Date
    Feb 2010
    Location
    Melbourne
    Posts
    10,247
    Total Downloaded
    0

    cut my face or thumb off??

    I tried using a photo on my phones FACE ID bio metrics- You may need to cut my face or thumb off

    Interesting security risk is that the phone back up includes that data of course!

    MY GOV. MY GOV ID and Two factor authentication applications I have on my phone have a device specific tag/certificate meaning duplication to a new device does take a lot more than a mirror duplication happily

    I can remotely wipe my phone- Call me Mr Paranoid

  2. #22
    Join Date
    Dec 2007
    Location
    Back down the hill.
    Posts
    29,769
    Total Downloaded
    0
    Quote Originally Posted by p38arover View Post
    ^^ One never stops learning.
    Or in this case, two.
    If you don't like trucks, stop buying stuff.
    http://www.aulro.com/afvb/signaturepics/sigpic20865_1.gif

  3. #23
    Join Date
    Mar 2012
    Location
    Armstrong Creek, Qld
    Posts
    8,752
    Total Downloaded
    0
    Quote Originally Posted by V8Ian View Post
    Or in this case, two.
    Are you inferring that you were aware of the existence of "Matlow"?
    'sit bonum tempora volvunt'


  4. #24
    Join Date
    Jan 2010
    Location
    Brisbane
    Posts
    5,141
    Total Downloaded
    0
    Quote Originally Posted by NavyDiver View Post
    I tried using a photo on my phones FACE ID bio metrics- You may need to cut my face or thumb off

    Interesting security risk is that the phone back up includes that data of course!

    MY GOV. MY GOV ID and Two factor authentication applications I have on my phone have a device specific tag/certificate meaning duplication to a new device does take a lot more than a mirror duplication happily

    I can remotely wipe my phone- Call me Mr Paranoid
    I think too much responsibility is placed on customers, as there is a scam going around where crims hijack an email and change the bank account number but not the name, and the bank will process payments even though the two don't match! Also I watched a doco about scams in the UK and quite a lot seems to be done with inside help from bank employees, shop employees and postal workers.
    2005 D3 TDV6 Present
    1999 D2 TD5 Gone

  5. #25
    DiscoMick Guest
    Had an interesting discussion with a data security expert for the Qld govt while camping on Saturday.
    He said the main problem with the Optus hack was not what ID it required, but the fact the verification details were retained rather than being deleted.
    He said retaining details meant Optus had a duty of care to keep them safe. He also said the Optus breach was not that difficult, but wouldn't say how it was done.
    He also said he tells Qld govt bodies to delete the verification details, and ask for them again if it is necessary to reverify.
    So the result is stringent verification plus deleted details.
    Apparently one problem is federal terrorism legislation passed in 2017 forces telcos to retain identification details for up to 2 years after an account ends, which can mean up to 6 years.
    So Optus, and probably all telcos, are storing that information to comply with federal laws and so become attractive targets for hackers. So maybe Optus is being unfairly blamed for trying to comply with federal laws.
    Sounds like the laws need to be changed to cut the retention times and increase deletion.

  6. #26
    Join Date
    Jan 1970
    Location
    Avoca Beach
    Posts
    14,152
    Total Downloaded
    0
    On 26/9 Optus emailed me saying that my name address, DOB and home address were hacked and in bold " No ID document numbers or details have been affected" Last night I get a text saying "Cyberattack update: Confirming only the licence number on your Driver Licence was exposed, not the card number.. Your State or Teritory government willprovide advice on any action that you may need to take via their website" I wonder which is correct. I have entered a chat with Optus but don't anticipate any answer. This is really ****ty. At the time I wondered if they actually knew or may have lied . So I am in limbo. Regards PhilipA

  7. #27
    Join Date
    Jan 1970
    Location
    NSW SW Slopes
    Posts
    12,030
    Total Downloaded
    0
    I'm a grain grower who sells grain to grain buyers. Quite some years ago most grain buyers agreed to centralise their grower details with a 3rd party business although my prime buyer maintains their own details. That 3rd party this year upgraded their online system then requested growers by email to log onto their new system with their existing logon to check their details. However they set the new system to require additional indentification proof such as a driver's licence, Medicare or passport number at the initial logon. Well before the Optus incident I declined to hand over any such indentification on the basis that they have no right to require such information from me and my providing such information increases the risk of identify theft. I don't know how this will progress especially in light of the Optus incident but I don't need to update any personal information at this time, indeed I've not needed to update my details since the 3rd party arrangement commenced. Grain buyers pay direct to the grower, not to the 3rd party.
    MY21.5 L405 D350 Vogue SE with 19s. Produce LLAMS for LR/RR, Jeep GC/Dodge Ram
    VK2HFG and APRS W1 digi, RTK base station using LoRa

  8. #28
    DiscoMick Guest
    If I was you I would change my licence number, just to be sure.
    Quote Originally Posted by PhilipA View Post
    On 26/9 Optus emailed me saying that my name address, DOB and home address were hacked and in bold " No ID document numbers or details have been affected" Last night I get a text saying "Cyberattack update: Confirming only the licence number on your Driver Licence was exposed, not the card number.. Your State or Teritory government willprovide advice on any action that you may need to take via their website" I wonder which is correct. I have entered a chat with Optus but don't anticipate any answer. This is really ****ty. At the time I wondered if they actually knew or may have lied . So I am in limbo. Regards PhilipA

  9. #29
    Join Date
    Jan 1970
    Location
    Avoca Beach
    Posts
    14,152
    Total Downloaded
    0
    In NSW they will change your card number only and it costs $29 to be refunded by Optus , maybe one day in the far far future. STOP PRESS . I apparently am being given an Equifax account for one year to check whether anyone tries to steal my identity. Of course I went through the motions and applied only for the Optus special number not to work, so more time on the phone tomorrow. Regards PhilipA

  10. #30
    NavyDiver's Avatar
    NavyDiver is offline Very Very Lucky! Gold Subscriber
    Join Date
    Feb 2010
    Location
    Melbourne
    Posts
    10,247
    Total Downloaded
    0
    Quote Originally Posted by PhilipA View Post
    In NSW they will change your card number only and it costs $29 to be refunded by Optus , maybe one day in the far far future. STOP PRESS . I apparently am being given an Equifax account for one year to check whether anyone tries to steal my identity. Of course I went through the motions and applied only for the Optus special number not to work, so more time on the phone tomorrow. Regards PhilipA
    Vic roads rego due- when online it offered two 2 factor verification methods. Bravo Zulu Vic Roads I would say

    Optus business phone account for two weeks 4 years ago. The phones which did not work and cost me $$$$$$$$$ got all my details.

    such is life

Page 3 of 4 FirstFirst 1234 LastLast

Tags for this Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Search AULRO.com ONLY!
Search All the Web!