Desert Schools Credit Union let me create a password that contains characters that are not letters or numbers, but it won't let me login with that password.
when software discombobulates
20160105
Entered by: Ben Simo
20131125
Entered by: Ben Simo
You've been throttled
what does this mean i feel abused pic.twitter.com/uhvhukZZaF
— lauren sanderson (@laurenthellama) November 15, 2013
20131013
Entered by: Ben Simo
Healthcare.gov exposes existing usernames and email addresses
As a fundamental principle in software system security, it is considered wrong to expose anything about protected data in a system in the error messages that are returned to those who are not authorized to access that data.
For example, if one enters an incorrect username and/or password, you do not tell them whether the username or password is incorrect. Confirming that a username exists is useful information to someone who is trying to gain unauthorized access: it allows them to narrow their attack to a known username and/or combine the username with other info to aid in guessing or otherwise gaining access to the password. Such information is useful in social engineering.
GIVEN that not disclosing information to the unauthorized in error messages is a practice that is expected of any competent web application developer
AND that Healthcare.gov is a system many are required by law to use
AND that Healthcare.gov contains private information,
THEN let's take a look at what we get from Healthcare.gov :


PS: Given a real constraint on unique user names obfuscating the fact that a username exists may not be easy. However, one could at least present a more ambiguous error message along the lines of "That username is invalid. Please try another." Or, let the system generate the usernames in a way that no conflicts are created. (See comment below.)
20110907
Entered by: Ben Simo
Never share your computer with your girlfriend
I found this old bug report in the Mozilla bug database. Is exposing liars a bug or a feature? ;)
Bug 330884 - When different users on one system choose to save or not save passwords for sites, any other user can see sites they not only saved passwords for but can also see what other users have been saving/never saving passwords for.
naomirocks 2006-03-17 15:48:21 PST
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.1) Gecko/20060111 Firefox/1.5.0.1
This privacy flaw has caused my fiancé and I to break-up after having dated for 5 years.
Basically, we share one computer but under separate Windows XP user accounts. We both use Mozilla Firefox -- well, he used to use it more than I do but now we don't really use it. The privacy flaw is this: when he went to log-in under his dating sites (jdate.com, swinglifestyle.com, adultfriendfinder.com, etc.), Mozilla promptly asks whether or not he'd like Firefox to save the passwords for him. He chose never, obviously. However, when he logged off his user account, and I logged onto my Windows XP account X amount of days later, I decided to use Firefox because hey -- it loaded everything much more efficiently, was better to work on with website designs and is a lot more stable than IE7beta2.
Firefox prompted whether or not I'd like it to save my password for logging into my website. I chose never and changed my mind. I went into the Password Manager to change the saved password option from Never to Always and that's when I saw all these other sites that had been selected as "Never Save Password." Of course, those were sites I had never visited or could ever dream of visiting.
Then I realized who, how and what... and sh*t hit the fan. Your browser does not efficiently respect the privacy of different users for one system.
Reproducible: Always
20110831
Entered by: Ben Simo
Correct Horse Battery Staple
@throg tweets: I tried to change my password to "correcthorsebatterystaple" and got this error message.
Better pick a password that is easier for computers to guess.
In case you don't know why someone would pick such a password, check out this xkcd comic:
20110828
Entered by: Ben Simo
You tried to create a new account
Trying to order ink from the HP Home and Home Office Store to which the HP printer driver software on my computer took me, I get the following:
You tried to create a new account using an e-mail address that matches an existing account. To continue your checkout process, do not fill in the password fields.I've never ordered anything from an HP online store. How can my e-mail address match an existing account? If I continue the checkout process without filling in the password fields, will this order be associated with some existing account without any credential verification? Or will it not be associated with any account? Will I be able to access this order if there is no account associated with it?
Some later experimentation revealed that this store accepted my HP Passport single-sign-on credentials that I've used for support with HP Mercury test tool products. I never would have expected that account to be the same account I need to use to order ink cartridges for my home printer.
20110820
Entered by: Ben Simo
I'm going to ask you a question
What is a more secure way to secure people's data on your website than the typical username and password pairing?
Someone at UPS seems to think an answer to a stupid question is better. These aren't just any stupid questions. These are question that are likely answerable by anyone who knows you. If you pick the right question, there's a good chance that you've even posted the answer to the question on your blog, on Facebook, or even Twitter. So, what is a stupid question? Take a look:
No, these aren't the so-called "security questions" that are used in addition to a username and password pair. This question and answer is being used where a password would typically be found.
All that is needed to access an account is an email address and the answer to a question.


Narrowing people's thinking as they select passwords, and later giving the same clue at login seems almost as insecure as asking for no more than a phone number and zip code. Oh, but that's already taken by Century Link*.
formerly known as Qwest,
20110817
Entered by: Ben Simo
Certain information
I try to reset the password for a local Windows Server account and get the following warning dialog.
It warns that resetting the password might cause IRREVERSIBLE LOSS of "certain information". If the information that will be lost is certain, why doesn't this warning tell me what information will be lost and what won't be lost?
And what is this stuff about a disk? Who creates password reset disks for every user of a server? I haven't. Should I?
Wanting additional information, I click the Help button. This opens a local help document that explains what data will no longer be acceptable. However, even this refers to "some types of information" and gives an "including" list. It doesn't give a full inclusive list. Or if this list is inclusive, that isn't clear from the help document.
If you are going to tell me that my actions might cause damage to "certain information", please have the courtesy to give me sufficient details to make an informed decision.
20110623
Entered by: Ben Simo
20110428
Entered by: Ben Simo
20100213
Entered by: Anonymous
Error logging in
Michael F reports:
Got this using my Username and Password, and an updated one from the site.
So what is the Error?
It is generally a good idea not to disclose information that could help someone gain unauthorized access to your system, but a bit more information than this could help real customers.
20100129
Entered by: Ben Simo
Ambiguous authentication
osma: updating my computer. apparently one of many updates has an issue, but which one? #packagekit #fail
Security features like this can be useful in protecting computers from malware but ONLY IF the user is given sufficient information to make intelligent decisions.
20100128
Entered by: Anonymous
20100115
Entered by: Ben Simo
That was the wrong password
I got the above screen after failing to login to my Meetup account to RSVP for a meeting.
As a user, I like that it tells me that I used the correct email address but wrong password.
However, this system has just verified information without authentication. It tells me that a valid user email address was used. This information could be helpful to someone trying to gain unauthorized access.
Now, in this case, I don't think disclosing that email accounts exist is a huge deal. This is a social networking site. This is not a banking system. This is not a medical records system. It is not an interface to access private information. Meetup profiles are public and searchable on the web -- although not email addresses. I say no problem in the context of this site.
For other systems, giving non-authenticated people information that narrows down access credential options could be a huge security problem.
20100113
Entered by: Ben Simo
Passwords in client-side Javascript
Tweeted by MatTipton.

Wow! Don't put your password on a sticky note under the keyboard when you can hide it in client-side Javascript code. This may meet the technical requirements given to the developer but it fails to meet the expectations, and purpose, of access control systems.
20091231
Entered by: Ben Simo
The password is already in use with another account

Wow! If the message is correct, this system appears to be disclosing passwords used by other users.
Entered by: Ben Simo
Please forget your password again
20091230
Entered by: Ben Simo
Entered by: Ben Simo
Return status indicates that the value is not correct

I think we may need someone to translate this developer-speak to English.
20091229
Entered by: Ben Simo

Comment
5 Comments







