Elektrine lite

← Feed

@tychotithonus@infosec.exchange

Post #3967599

2026-07-20 16:31 UTC

Add ID.me to the list of services that think it's a good idea to use third-party link tracking for password reset links. You are incenting the opposite of good security awareness. And you are not some random tiny website. Your entire fscking business is supposed to be secure authentication. Do better.

Replies (4)

  • @karlauerbach@sfba.social 2026-07-20 18:05

    @tychotithonus@infosec.exchange I have trouble accepting anything rooted in a country code top level domain (ccTLD), such as .me or .it, as being secure for use identifying people in the US. ccTLD domains are effectively controllable by the political forces in the country they represent. Some countries have delegated operation of their ccTLD to private operators. (ccTLDs are run, to the main, reasonably well. I am speaking here of possibilities not necessarily present realities.) Because DNS queries typically contain the entire set of DNS labels, it is possible for a ccTLD operator to capture nearly all queries to that ccTLD (by setting very short TTL values) and feeding controlled (or manipulated) answers (even with DNSSEC enabled.) I wrote a bit about this twenty years ago, but more about root servers than ccTLD servers. "What Could You Do With Your Own Root Server?" https://www.cavebear.com/old_cbblog/000232.html

    Open ##3967598

  • @tychotithonus@infosec.exchange Reminds me of this gem:

    Open ##3972976

  • @ChasMusic@ohai.social 2026-07-21 23:30

    @tychotithonus@infosec.exchange I don't remember which sites do login.gov and which use id.me, but for the ones using id.me ¿is there a path to switch to login.gov instead?

    Open ##3999248

  • @ChasMusic@ohai.social 2026-07-21 23:29

    @tychotithonus@infosec.exchange Is it feasible to reverse-engineer the URL to remove the tracking portion,for example, to copy and edit the link go directly without tracking to https://api.id.me/passwords/e50fdcd3d952eec708 and so on?

    Open ##3999265