Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Facebook security isn't nearly good enough . . .

Pretty sure most cases where people's accounts get hacked have nothing to do with the security of the website, except inasmuch as the site fails to provide an authenticator. Most "hacking" involves getting a computer virus or entering your password into a site that is not actually Facebook.



This is true. On the other hand, online banking security starts from "the client computer is compromised", and a new service that says "you're fully liable if your machine is hacked" will have... problems getting traction.


"online banking security starts from 'the client computer is compromised'"

Facebook currently (or did) reset the password by having you identify the names of your friends using their pictures. I could see this as a way to authenticate a transaction.


Really? None of your friends have pictures of cats or their babies or grainy shots of them and four other friends as their profile pictures? Because sometimes it feels like half of mine do.


At that point your requiring about as much effort to authorize the transaction as you would be to enter a card number.

Also not sure how secure that would be , how difficult would it be for a would be attacker to find out who was in the images?

I imagine a reverse image search could be fruitful.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: