article thumbnail

E-Verify’s “SSN Lock” is Nothing of the Sort

Krebs on Security

After verifying my email address, I was asked to pick a strong password and select a form of multi-factor authentication (MFA). Password reset questions selected, the site proceeded to ask four, multiple-guess “knowledge-based authentication” questions to verify my identity.

Passwords 297
article thumbnail

MyEquifax.com Bypasses Credit Freeze PIN

Krebs on Security

The portal asked me for an email address and suggested a longish, randomized password, which I accepted. SSN and DOB data is widely available for sale in the cybercrime underground on almost all U.S. I chose an old email address that I knew wasn’t directly tied to my real-life identity.

Passwords 270
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

News alert: Badge expands availability of ‘Enroll Once and Authenticate on Any Device’ software

The Last Watchdog

By eliminating passwords and stored secrets, Badge bolsters Radiant Logic’s extensible identity data platform to accelerate strategic initiatives such as digital transformation, Zero Trust, automated compliance, and data-driven governance. This sets the stage for a more connected and secure online future for everyone.”

article thumbnail

Generated Passwords, UX and Security Absolutism

Troy Hunt

The service was obviously rather popular because within days the tech (and mainstream) headlines were proclaiming that thousands of hacked Disney+ accounts were already for sale on hacking forums. So why doesn't every site take away the ability for people to choose their own passwords? It doesn't matter who generated the password.