October 20, 2018
Example of bad security model and "We have noticed an unusual activity in your account."
Of course sometimes companies use any little reason to get more pieces of personal information, like the mobile phone number. For example, it makes absolutely no sense to ask for a phone number after "unusual account activity" has been already detected. Asking the one user who is logging in to provide his phone number (and possibly linking it to the account as 2FA or account recovery channel) actually is very bad idea in this situation! Because if attacker already has password on hand he can also link his phone number thus effectively preventing the account owner from logging into account forever.
Threat modelling can help understand such situations and prevent them.
Labels: account, security, threat model
October 18, 2018
Research on why iTunes is launched sometimes when I wake up macbook
Labels: bluetooth, headset, knock-knock, osx, resume, sleep, wakeup