UK banks like to make you pick a "memorable word" and then will ask you for two or three letters when you log in.
Given even two letters, there usually won't be many possibilities...
UK banks like to make you pick a "memorable word" and then will ask you for two or three letters when you log in.
Given even two letters, there usually won't be many possibilities...
@timelordiroh yes
@ryanc this might just be the dumbest way to 2fa without actually doing 2fa that I have ever seen. Is it common in UK?
@ryanc It has long been speculated that a statistical correlation exists between the familiarity of a player with a word, and the number of expected wordle turns the player will require to solve for the word; and that this might have practical applications in the field of authentication mechanisms. In this paper, we
@bh11235 now that you mention it, I think I once wrote a CTF challenge that was a lot like wordle, except it was intended to force the players to automate it.
@ryanc … but you only get a few wrong guesses before it locks.
@BenAveling If you observe one login, you can probably guess the word before it locks.
@BenAveling It's just wordle.
@ryanc interesting.
back of the envelope calculation for that attack, assuming 6 letter words, chosen randomly, 3 letters, chosen randomly, 5 guesses, attacker has full knowledge of those 3 letters => almost 70% chance of guessing.
Much harder if the attacker knows the letters but not the exact locations.
Also a lot harder if the bank is deliberate in its choosing of letters rather than completely random - many words have some combination of 3 letters that are a complete 100% giveaway and other combinations that are very much not.
@BenAveling The positions are specified by the prompt, the customer chooses the word. The word not being chosen randomly matters a lot.
Sure, an attacker can't get into every account, but if they phish 100 people, they'll probably be able to get into most of them.
@ryanc how did we segue to phishing?
@BenAveling My original post was implicitly about phishing.
The banks claim the reason they only ask for two or three of the letters is to prevent replay attacks (capture via phishing or man-in-the-browser) from being used to login.
This feature is touted as a sort of one time password MFA, but it absolutely is not.
@ryanc if you’re mitm’d then it doesn’t matter how good your password is…
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.