|
Post by Chopsen on Aug 30, 2022 9:16:48 GMT
Can you bypass face recognition by holding up some photo I'd to the camera? Like a driver's licence.
|
|
|
Post by Chopsen on Aug 30, 2022 9:18:56 GMT
And while I'm not a techy bod like others here, my first reaction was to think "bullshit."
|
|
|
Post by Fake_Blood on Aug 30, 2022 9:22:42 GMT
Are there some actual technicians on FG? Like anyone in electronic or mechanical engineering?
|
|
|
Post by dfunked on Aug 30, 2022 9:22:48 GMT
Yeah, there's a definite whiff of bullshit about this.
|
|
Bongo Heracles
Junior Member
Technically illegal to ride on public land
Posts: 4,661
|
Post by Bongo Heracles on Aug 30, 2022 9:25:32 GMT
Can you bypass face recognition by holding up some photo I'd to the camera? Like a driver's licence. On old android phones, yeah, but banking apps dont (or shouldnt) accept that kind of weak biometrics as a pass (and phones with that kind of facial recognition have fingerprint ID, which they do accept). iPhones, which she has, dont recognise the picture, as such, they use more of a LIDAR type approach, sending out a beam to do 3D mapping of your face (which is why it works with sunglasses, because it doesnt care if the lens is dark, the beam passes through it anyway). It also needs you to be looking directly at the screen so you cant unlock it when someone is asleep or from the side of them. It will never work with a photo as its 2D, obviously. So, yeah, to get into her phone, they either needed her to be awake and looking directly at it, or her 4 digit PIN.
|
|
sport✅
Junior Member
notice me senpai
I want to claim my tits
Posts: 2,326
|
Post by sport✅ on Aug 30, 2022 9:28:17 GMT
What if they 3D printed her head?
|
|
Bongo Heracles
Junior Member
Technically illegal to ride on public land
Posts: 4,661
|
Post by Bongo Heracles on Aug 30, 2022 9:28:40 GMT
That would also work
|
|
mrharvest
New Member
Registered 18 years ago Posts 5,718
Posts: 373
|
Post by mrharvest on Aug 30, 2022 11:54:46 GMT
Eeeeeeeeeehhhhh..... if I was the case worker on this, I would probably have decided negligence. [...] To compromise one thing, maybe. To compromise everything? Nah, she had passwords and PINs written on a post it in her purse. I definitely call bullshit on this one. I'm not quite so sure. She was fairly adamant in her comments that she hadn't written anything down, and I don't think people usually write down their card or phone PIN. I would have guessed there is some other attack vector. Is it definitely an iPhone that doesn't have Touch ID, i.e. not an iPhone SE? The Santander app could also be unlocked with a fingerprint and that would effectively give a single point of failure. In the Twitter thread the lady said that someone had transferred money from her savings account to the current account, so they definitely were able to access the banking app. The Twitter thread mentioned similar types of attacks at different gyms, it's not a bad MO as the type of people who go to a Virgin gym would probably have a fair bit of money in their account. Dunno, my initial impression wasn't that she had written everything down, but maybe.
|
|
askew
Full Member
Posts: 6,831
|
Post by askew on Aug 30, 2022 11:57:43 GMT
What if the fallback device PIN was: 0000 1234
|
|
Bongo Heracles
Junior Member
Technically illegal to ride on public land
Posts: 4,661
|
Post by Bongo Heracles on Aug 30, 2022 12:24:01 GMT
I'm not quite so sure. She was fairly adamant in her comments that she hadn't written anything down, and I don't think people usually write down their card or phone PIN. I would have guessed there is some other attack vector. Is it definitely an iPhone that doesn't have Touch ID, i.e. not an iPhone SE? The Santander app could also be unlocked with a fingerprint and that would effectively give a single point of failure. In the Twitter thread the lady said that someone had transferred money from her savings account to the current account, so they definitely were able to access the banking app. The Twitter thread mentioned similar types of attacks at different gyms, it's not a bad MO as the type of people who go to a Virgin gym would probably have a fair bit of money in their account. Dunno, my initial impression wasn't that she had written everything down, but maybe. I would be adamant and kicking up a stink on twitter if I had several grand at stake. And its the same difference with faceID and the fingerprint reader. They would still have to have her present to unlock her phone and fire up the app with her finger print, same as faceID. Its the same principle just unlocking it with different things. But, regardless, I have cracked the case. Realistically, they cant get into her phone without her being present or without her PIN, so either: - Inside job - The insider repositioned a security camera to point to a PIN pad over a period of weeks/months - Thieves collate PIN numbers against guest register - insider left the gates open and revealed best way to get into lockers - thieves clean the place out - Everyone who has the same PIN for phone and card is fucked - party Or: - She had her PIN written down with her icloud passwords and maybe a few household bills for good measure.
|
|
|
Post by Chopsen on Aug 30, 2022 15:10:20 GMT
As anybody who deals with the public as a part of their job in any capacity knows for certain: People will happily lie through their teeth if the alternative is that they look even slightly foolish in front of complete strangers.
She had a scrappy notebook or something in her handbag with various passwords and PINs written down, and she re-uses the same PINs and passwords across all her devices and accounts.
OR
The lockers used a numerical combination lock. She used the same combination for her locker as she uses for her phone. Someone watched her do that, waited for her to leave, opened her locked and lucked out.
|
|
cubby
Full Member
doesn't get subtext
Posts: 6,403
Member is Online
|
Post by cubby on Aug 30, 2022 15:26:34 GMT
I'm sure people do it but I find it surprising she put her phone in the locker as well as her purse and keys. I don't partly for that reason, that everything is gone if someone breaks in. Also music, but yeah.
|
|
|
Post by 😎 on Aug 30, 2022 15:36:08 GMT
Yeah, that whole entire thread seems weird to me. Not even government entities can break into the banking apps or Apple IDs without a convenient pin or passcode written down on a post-it. The idea that they got into absolutely everything and then went on a physical shopping spree within the span of a single gym visit is just weird.
|
|
dmukgr
Junior Member
Posts: 1,531
|
Post by dmukgr on Aug 30, 2022 15:38:14 GMT
I’m even more vigilant in that I don’t go to the gym. Yup, purely to avoid having my phone stolen I’ve sacrificed being svelte and muscly.
|
|
|
Post by Bird Of Prey on Aug 30, 2022 15:46:31 GMT
Are there some actual technicians on FG? Like anyone in electronic or mechanical engineering? I've a certificate that says I used to be an electronic engineer (avionics) if that's any good. It was a while back, so I did valve theory...
|
|
|
Post by Fake_Blood on Aug 30, 2022 16:42:24 GMT
Are there some actual technicians on FG? Like anyone in electronic or mechanical engineering? I've a certificate that says I used to be an electronic engineer (avionics) if that's any good. It was a while back, so I did valve theory... So cab I surmise you didn’t end up in avionics? Was kind of amazed when I found out all that stuff runs on 115V at 400Hz. I got a degree in medical electronics. I make sure our devices don’t zap anyone, whilst also making sure they don’t break when a patient intentionally gets zapped.
|
|
sport✅
Junior Member
notice me senpai
I want to claim my tits
Posts: 2,326
|
Post by sport✅ on Aug 30, 2022 17:01:51 GMT
No way she left it in a locker. You're not really gyming these days if you're not filming your form. Or taking selfies for Insta.
|
|
|
Post by Bird Of Prey on Aug 30, 2022 19:48:41 GMT
I've a certificate that says I used to be an electronic engineer (avionics) if that's any good. It was a while back, so I did valve theory... So cab I surmise you didn’t end up in avionics? Was kind of amazed when I found out all that stuff runs on 115V at 400Hz. I got a degree in medical electronics. I make sure our devices don’t zap anyone, whilst also making sure they don’t break when a patient intentionally gets zapped. I did. I spent almost two decades in avionics, mostly telecoms (transmitters, receivers, satcomms), some weapon systems and encryption and then into programming. It's been a long time since I checked anything with a DVM (25 years or so).
|
|
|
Post by Fake_Blood on Aug 30, 2022 20:25:06 GMT
So cab I surmise you didn’t end up in avionics? Was kind of amazed when I found out all that stuff runs on 115V at 400Hz. I got a degree in medical electronics. I make sure our devices don’t zap anyone, whilst also making sure they don’t break when a patient intentionally gets zapped. I did. I spent almost two decades in avionics, mostly telecoms (transmitters, receivers, satcomms), some weapon systems and encryption and then into programming. It's been a long time since I checked anything with a DVM (25 years or so). Reads like the résumé of someone that went missing in a Tom Clancy novel.
|
|
|
Post by Bird Of Prey on Aug 30, 2022 20:27:13 GMT
I did. I spent almost two decades in avionics, mostly telecoms (transmitters, receivers, satcomms), some weapon systems and encryption and then into programming. It's been a long time since I checked anything with a DVM (25 years or so). Reads like the résumé of someone that went missing in a Tom Clancy novel. Only a lot duller. I was one of the people who fixed the stuff that the interesting people did interesting things with until they broke them.
|
|
Lukus
Junior Member
Posts: 2,723
|
Post by Lukus on Aug 30, 2022 21:34:04 GMT
Still, at least you got a cool pirate hat for your troubles
|
|
cubby
Full Member
doesn't get subtext
Posts: 6,403
Member is Online
|
Post by cubby on Sept 12, 2022 14:48:29 GMT
You guys might be of help with this issue.
At work we're in a big 2 story concrete building, spanning 10000 sq ft. I want to improve the shoddy WiFi extenders that were put in 7-8 years ago as there's so many dark spots and drop outs. There's also complete areas that don't get any signal that would need to be wired to in our current set up if we were to continue that system, but at least they're mostly plasterboard rooms.
I'm investigating the viability of switching to a mesh system, but I'm thinking it might be more cost effective to just improve the current access points that are in place. Anyone got experience of using mesh in a large workplace?
|
|
|
Post by Fake_Blood on Sept 12, 2022 14:58:29 GMT
I’d go for some Ubiquity gear, basically a bunch of antennas that all go to one router over existing cabling.
|
|
dogbot
Full Member
Posts: 8,738
|
Post by dogbot on Sept 12, 2022 15:16:48 GMT
If you've got lots of users in that area, you'll probably need better than the bandwidth that a cheap mesh WiFi backhaul will be able to provide.
Cheap networking gear will give you cheap performance.
|
|
Bongo Heracles
Junior Member
Technically illegal to ride on public land
Posts: 4,661
|
Post by Bongo Heracles on Sept 12, 2022 15:30:29 GMT
Same with everything else, it depends on money. Have you been given a budget for it?
|
|
cubby
Full Member
doesn't get subtext
Posts: 6,403
Member is Online
|
Post by cubby on Sept 12, 2022 15:37:16 GMT
Very few users, which hopefully gives me some leeway. I'd say there would be a max of 5 users, and that would be rare. Coverage is more important than speed.
I stupidly said we'd be looking at about £300 initially. If it was completely down to me it'd be double that.
|
|
Bongo Heracles
Junior Member
Technically illegal to ride on public land
Posts: 4,661
|
Post by Bongo Heracles on Sept 14, 2022 10:33:32 GMT
Youre stuck with consumer gear. Just get 300 quids worth of whatever the best selling mesh stuff is on amazon that will cover your office. In other news: A biscuit for whoever can spot the problem with Nintendos technical support for getting Splatoon 3 working
|
|
dogbot
Full Member
Posts: 8,738
|
Post by dogbot on Sept 14, 2022 10:40:44 GMT
Heh 😀
|
|
|
Post by DJCopa on Sept 14, 2022 10:44:54 GMT
HEY EVERYONE - COME ON IN!
|
|
|
Post by 😎 on Sept 14, 2022 15:07:26 GMT
|
|