stevio
Member of DD Central
Posts: 2,065
Likes: 894
|
Post by stevio on Nov 11, 2015 17:05:31 GMT
Unlike others who anonymise usernames, FundingSecure post the full username on loans, enabling the lender to be identified, how much they have invested in that loan and also compromising security by giving half of only 2 pieces of identity needed to log into your account. There are multiple password programs that go through millions of password combinations in seconds.
Do you consider this a security issue?
|
|
oldgrumpy
Member of DD Central
Posts: 5,087
Likes: 3,233
|
Post by oldgrumpy on Nov 11, 2015 17:25:30 GMT
Yes. It is time really that FS replaced this with a three stage sign in, and called me o****g (or something else!) in their investor lists.
|
|
ablender
Member of DD Central
Posts: 2,204
Likes: 555
|
Post by ablender on Nov 11, 2015 18:28:17 GMT
Why? It is really annoying. Currently there is a guy who is annoying everyone on SS and the only thing you see is s*****r. Why can't we see the user name? After all you all show your user name here and it does not have to be your name and surname - so I do not see where the security risk comes in.
|
|
SteveT
Member of DD Central
Posts: 6,875
Likes: 7,924
|
Post by SteveT on Nov 11, 2015 18:34:27 GMT
Why? It is really annoying. Currently there is a guy who is annoying everyone on SS and the only thing you see is s*****r. Why can't we see the user name? After all you all show your user name here and it does not have to be your name and surname - so I do not see where the security risk comes in. The security risk arises because FS opt to use your website login ID (in full) to identify you on loans and only use 1 step login security.
|
|
ablender
Member of DD Central
Posts: 2,204
Likes: 555
|
Post by ablender on Nov 11, 2015 18:40:25 GMT
Then the issue is not the use of the username but the need for an extra layer of security while logging in. FC uses the full user name and there is no risk. They do however add a security question apart from the password.
|
|
ilmoro
Member of DD Central
'Wondering which of the bu***rs to blame, and watching for pigs on the wing.' - Pink Floyd
Posts: 11,315
Likes: 11,524
|
Post by ilmoro on Nov 11, 2015 18:45:21 GMT
Then the issue is not the use of the username but the need for an extra layer of security while logging in. FC uses the full user name and there is no risk. They do however add a security question apart from the password. My FC log in isnt my displayed user name.
|
|
SteveT
Member of DD Central
Posts: 6,875
Likes: 7,924
|
Post by SteveT on Nov 11, 2015 18:49:53 GMT
Then the issue is not the use of the username but the need for an extra layer of security while logging in. FC uses the full user name and there is no risk. They do however add a security question apart from the password. The FC user name has nothing to do with your login ID, for which they use your registered email address. [crossed with ilmoro]
|
|
ablender
Member of DD Central
Posts: 2,204
Likes: 555
|
Post by ablender on Nov 11, 2015 18:54:43 GMT
You are both correct on that. So that might be a change that can be done here. But I like the idea of seeing the user name. If someone is stabbing me in the back, I want to know who.
|
|
SteveT
Member of DD Central
Posts: 6,875
Likes: 7,924
|
Post by SteveT on Nov 11, 2015 18:59:54 GMT
You are both correct on that. So that might be a change that can be done here. But I like the idea of seeing the user name. If someone is stabbing me in the back, I want to know who. Pretty hard to do that on FS anyway but, out of interest, what difference does it make whether someone is listed as deviousgit or d********t ?
|
|
oldgrumpy
Member of DD Central
Posts: 5,087
Likes: 3,233
|
Post by oldgrumpy on Nov 11, 2015 19:01:29 GMT
Rogues up to mischief wouldn't be able to log in with d********t
|
|
ablender
Member of DD Central
Posts: 2,204
Likes: 555
|
Post by ablender on Nov 11, 2015 19:03:16 GMT
I use eBay regularly and I saw a lot of abuses cloaked under the idea of private buyers. The same will happen everywhere.
|
|
SteveT
Member of DD Central
Posts: 6,875
Likes: 7,924
|
Post by SteveT on Nov 11, 2015 19:09:06 GMT
Rogues up to mischief wouldn't be able to log in with d********t Totally agree that using website login ID as the lender identifier / username is crazy. My point was really that usually someone can choose any username they like (baz**** springs to mind) without revealing their true identity.
|
|
stevio
Member of DD Central
Posts: 2,065
Likes: 894
|
Post by stevio on Nov 11, 2015 21:10:01 GMT
I use eBay regularly and I saw a lot of abuses cloaked under the idea of private buyers. The same will happen everywhere. Talking eBay, PayPal has become hackers choice because they to give away your username (email) so hackers need only guess single password
|
|
ribs
Probably not James Marshall
Posts: 148
Likes: 151
|
Post by ribs on Nov 12, 2015 10:16:32 GMT
There are multiple password programs that go through millions of password combinations in seconds. You are misunderstanding how this technology works. The method you describe is called 'brute force'. Yes, there are programs that can "go through" millions of password combinations in seconds, often using rainbow tables or random keyspace attacks... However, they tend to work against a local file, such as a hashed and encrypted password file that may have been stolen. And if that file is stolen, your username is already exposed and there is nothing you can do about it. The biggest problem here for a potential attacker is the network. You cannot submit millions of passwords in seconds to the funding secure website. I am assuming (but I do not know) that Funding Secure's website has been designed in a sane way, where X amount of failed login attempts in Y amount of time ends up in a locked account, or at least flags and alerts someone. It's usually something like 3 attempts in 120 seconds or something. This action alone would stop the vast majority of attackers in such a method. Others may attempt it, if they maybe have a few passwords that they know a specific user likes to use, but most won't, and probably won't use a automated program to do it either. The bigger concern should be for people being "doxxed", where the user is stupid/naive/unfortunate enough to go and get their information leaked online and tied to their public online alias. Even then, I don't see Funding Secure being a particularly lucrative target. Depending on the attackers intent, a Facebook account can be much more valuable. How do you find your friends on Facebook? their email is the most accurate way, how do you login to Facebook again? oh yeah, email address and password. For all it's faults, Facebook actually does security fairly well from a technical standpoint. Whilst I understand your intentions are entirely pure, I'm sorry to say you're simply wrong here, exposing the username isn't really a security risk, and if it is, it's a tiny one. In future, just use random usernames for each site you use if it concerns you that much (this will help against being doxxed), and, for the love of all that is good and pure in the world, use different passwords for every site you visit, including this one. Can't remember all those passwords? No, neither can I, hence I use LastPass. I literally have no idea what my password is to most things, but LastPass has done and excellent job of making new passwords and remembering them for me. And yes, LastPass is about as secure as it gets right now, just pick a strong and memorable master password as your master password is what encrypts all the other data (if you forget it, you're stuffed, essentially). LastPass can generate some pretty bad-ass passwords: X8gCeaWeo6BW8mD9Kej3WpMGRrjbV0KopRUd6SIQ, I just asked it to make, for example. Good luck, stay safe, and don't be afraid of your username.
|
|
oldgrumpy
Member of DD Central
Posts: 5,087
Likes: 3,233
|
Post by oldgrumpy on Nov 12, 2015 10:35:28 GMT
"Good luck, stay safe, and don't be afraid of your username."
Gee, thanks ribs That's really reassuring!
Virginia Woolf it is then .... aaaaaaaaaaaahhh! Oops!
|
|