• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Products and services where the new version is not as good or has significant disadvantages as the old

Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Yeah but a secure password changed regularly should be secure.

The problem of course being that most people don't use a secure password.

The wisdom of changing it is, er, changing a bit. My current employer doesn't require that we change them at all. I believe there's now a reckoning that as long as you use enough bits of entropy (i.e. a long password, e.g. a sentence rather than a word) the only need to change it is if you think it may have been breached by way of social engineering, as a brute force attack on a very long password is near impossible.
 

BuhSnarf

Member
Joined
22 May 2010
Messages
754
Location
Leicester
Yeah but a secure password changed regularly should be secure.

Daily/weekly/monthly? What would you define as reguarly?

A password is still a single piece of vulnerable information that can be stolen instantly through phishing or keyloggers or good old fashioned social engineering. A changed password is still just something you know.

Your password is something you know, while 2FA is something (a device, usually) you have as well as something you know.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Your password is something you know, while 2FA is something (a device, usually) you have as well as something you know.

The key being that it's both of these things. If it's just something you have, if your phone gets nicked then people can get into everything. This has happened by way of SMS 1FA* by putting the SIM card in another unlocked device, for instance. (This is one way in which eSIMs are superior to physical ones - you can't!)

* i.e. just the phone bit, no password alongside it.
 

BuhSnarf

Member
Joined
22 May 2010
Messages
754
Location
Leicester
The key being that it's both of these things. If it's just something you have, if your phone gets nicked then people can get into everything. This has happened by way of SMS 1FA* by putting the SIM card in another unlocked device, for instance. (This is one way in which eSIMs are superior to physical ones - you can't!)

* i.e. just the phone bit, no password alongside it.
Sorry, should have emphasised the "as well as" in my response. Yes, you need both :)
 

3rd rail land

Member
Joined
30 Jan 2019
Messages
736
Location
Where the 3rd rail powers the trains
Yes, Microsoft's authenticator app is now thankfully becoming a standard across a lot of organisations. Aegis Authenticator is a good open source alternative, too.
My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.
Yeah but a secure password changed regularly should be secure.
The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.

I agree with the bloke on some of this but not all.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.

So he's about as competent as people who think Apple/Google Pay is less secure than physical contactless payment cards, then. That is, he isn't competent at all!

Clue: in both cases there is no authentication to get the code/make a payment with a physical token/card, but there is with a phone!
 

JamesT

Established Member
Joined
25 Feb 2015
Messages
4,834
So he's about as competent as people who think Apple/Google Pay is less secure than physical contactless payment cards, then. That is, he isn't competent at all!

Clue: in both cases there is no authentication to get the code/make a payment with a physical token/card, but there is with a phone!
That’s not quite accurate. There has been a recent push around phishing resistant MFA. App based authentication using methods such as OTP still have weaknesses. Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.

That's more specific than "token good, phone bad", however. Most token based MFA is just using RSA SecurID tags which lack any verification, at least in my observation.

Microsoft's implementation seems to work well in that you not only need the phone but a code displayed on the device you're trying to log in, which increases the chance you have both rather than only one, and thus reduces the likes of phishing and other social engineering type scams.
 

WesternLancer

Veteran Member
Joined
12 Apr 2019
Messages
15,012
Well if you want to reduce and reuse then fill a bottle from the tap and don't buy the single-use bottles at all. The single use PET bottles are not designed for reuse and can lead to other issues if reused.
Out of interest what’s the reason not to reuse?
I regularly re use the plastic bottles of water you get given for free on board train first class

Should I not be doing so?
 

jon81uk

Member
Joined
17 Aug 2022
Messages
1,099
Location
Harlow, Essex
Out of interest what’s the reason not to reuse?
I regularly re use the plastic bottles of water you get given for free on board train first class

Should I not be doing so?
The main reason is they are hard to clean and also when they get old and crinkle that makes crevices bacteria can remain in. There may also be a risk of plastic breakdown.
Generally using 2-3 times is fine, but if you need to reuse it a lot then get a bottle designed to be reused and washed.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,691
Location
Gwynedd
Not part of the Britannia group by any chance?
It wasn't a chain as far as I'm aware. Maybe part of a small chain if so!

I have stayed at a Britannia in Nottingham and never again. I think the Home Office eventually forced them to take photocopies of all guest IDs, even British citizens, as there was so much people trafficking and sex trafficking going on. The hotel itself was filthy. I think I'd rather stay in a university dorm room for the night instead!
 

WesternLancer

Veteran Member
Joined
12 Apr 2019
Messages
15,012
The main reason is they are hard to clean and also when they get old and crinkle that makes crevices bacteria can remain in. There may also be a risk of plastic breakdown.
Generally using 2-3 times is fine, but if you need to reuse it a lot then get a bottle designed to be reused and washed.
Thanks. Helpful info.
I should use my stainless bottle more.
The small plastic bottles are a handy size but I can see what you mean about scope for problems over time.
 

speedy1

Member
Joined
1 Sep 2023
Messages
331
Location
Mossley
Well if you want to reduce and reuse then fill a bottle from the tap and don't buy the single-use bottles at all. The single use PET bottles are not designed for reuse and can lead to other issues if reused.
Why are you preaching to me, when you replied to my previous comment in which I wrote "For water I try to remember my water bottle". Or did you not read the entire very very short comment and rushed to make a haughty quip ?
 

sor

Member
Joined
15 Nov 2013
Messages
780
That’s not quite accurate. There has been a recent push around phishing resistant MFA. App based authentication using methods such as OTP still have weaknesses. Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.
The highest end yubikeys have fingerprint readers, but the bulk of them just have a touch sensor (which can be used to confirm that someone - but not necessarily the right person - is physically present before the key can authenticate)
 

jon81uk

Member
Joined
17 Aug 2022
Messages
1,099
Location
Harlow, Essex
Why are you preaching to me, when you replied to my previous comment in which I wrote "For water I try to remember my water bottle". Or did you not read the entire very very short comment and rushed to make a haughty quip ?
There was no intention to make a “haughty quip”, I was just replying to the flippant statement “I see. Well.... another fine example of pretending the first two 'R's don't exist. As long as we recycle recycle recycle, that's three Rs!” where you were implying you are only interested in the reuse of single use bottles. This follow up where you now state you try to remember your own water bottle answers your own comment, the first two R of reduce and reuse do exist when you remember to.
 

Silent

Member
Joined
31 Mar 2016
Messages
736
Location
London
My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.

The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.

I agree with the bloke on some of this but not all.
Yep I don’t know my passwords but funnily enough quickly memorised my Xbox Microsoft password as I typed it in every time I signed in. But it was also shortened as I heard old x360 accounts can only accept shorter passwords. It’s an apple keychain type password so it made me question how easy it hard it is to really memorise them. The main reason we don’t memorise them is because we don’t have to type them in. But I guess also because we can have so many passwords.

== Doublepost prevention - post automatically merged: ==

So he's about as competent as people who think Apple/Google Pay is less secure than physical contactless payment cards, then. That is, he isn't competent at all!

Clue: in both cases there is no authentication to get the code/make a payment with a physical token/card, but there is with a phone!
Apple/Google pay are more secure although I heard with visa you can hack Apple Pay express checkout if you know how to.

I use a physical card because my credit card doesn’t work with Apple Pay. I think the plus side of physical card is that I memorise my PIN number since it asks once in a while.
 

BuhSnarf

Member
Joined
22 May 2010
Messages
754
Location
Leicester
It wasn't a chain as far as I'm aware. Maybe part of a small chain if so!

I have stayed at a Britannia in Nottingham and never again. I think the Home Office eventually forced them to take photocopies of all guest IDs, even British citizens, as there was so much people trafficking and sex trafficking going on. The hotel itself was filthy. I think I'd rather stay in a university dorm room for the night instead!
Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,691
Location
Gwynedd
Yeah but a secure password changed regularly should be secure.
In an ideal world, perhaps.

But in reality you've got keylogging (both hardware and software loggers), CCTV cameras pointed at computers, malware, insecure password storage, and these days people with supercomputers and quantum computing either being able to crack passwords or effectively break the algorithms we currently use to secure communications, at which point passwords will be visible to those with the resources to intercept such messages.

The National Cyber Security Centre (NCSC) recommends against having password rotation policies: https://www.ncsc.gov.uk/blog-post/problems-forcing-regular-password-expiry

Regular password expiry is a common requirement in many security policies. However, in the Password Guidance published in 2015, we explicitly advised against it. This article explains why we made this (for many) unexpected recommendation, and why we think it’s the right way forward.

Let’s consider how we might limit the harm that comes from an attacker who knows a user’s password. The obvious answer is to make the compromised password useless by forcing the legitimate user to replace it with a new one that the attacker doesn’t know. This advice seems straightforward enough.

The problem is that this doesn’t take into account the inconvenience to users - the ‘usability costs’ - of forcing users to frequently change their passwords. The majority of password policies force us to use passwords that we find hard to remember. Our passwords have to be as long as possible and as ‘random’ as possible. And while we can manage this for a handful of passwords, we can’t do this for the dozens of passwords we now use in our online lives.

To make matters worse, most password policies insist that we have to keep changing them. And when forced to change one, the chances are that the new password will be similar to the old one.

Attackers can exploit this weakness.

The new password may have been used elsewhere, and attackers can exploit this too. The new password is also more likely to be written down, which represents another vulnerability. New passwords are also more likely to be forgotten, and this carries the productivity costs of users being locked out of their accounts, and service desks having to reset passwords.

It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack. What appeared to be a perfectly sensible, long-established piece of advice doesn’t, it turns out, stand up to a rigorous, whole-system analysis.

The NCSC now recommend organisations do not force regular password expiry. We believe this reduces the vulnerabilities associated with regularly expiring passwords (described above) while doing little to increase the risk of long-term password exploitation. Attackers can often work out the new password, if they have the old one. And users, forced to change another password, will often choose a ‘weaker’ one that they won’t forget.

People simply have too many passwords to avoid password reuse, and if they are then forced to regularly change them, the chance of them creating secure, non-reused passwords is further diminished; it's too much for almost anybody to remember.

== Doublepost prevention - post automatically merged: ==

Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.
Yeah I don't mind as long as places are clean. Depending why I'm staying in the hotel, I'm often quite happy to accept a dated interior and a tiny TV in exchange for a lower price.

I'm a stickler for air conditioning in the summer though. In the winter I'm happy with a window which opens enough.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.

I agree with the bloke on some of this but not all.

The main advantage of password managers isn't that you don't know the password but that you're more likely to use a unique password for each account so a breach doesn't give someone access to more than one thing. That's why I use one.

Bits of entropy are the key to a password being secure, i.e. the longer the better, as long as they're not something like "passwordpasswordpasswordpasswordpassword" as someone might guess that. It doesn't overly matter if they are dictionary words or random letters and numbers, the key is simply that they are as long as reasonably possible. This sentence, for example, would be better than a^$1@Pq - that's short so is brute forceable. While it might seem a normal sentence may be more easily brute forced, that isn't so because there are infinite numbers of words to try, whereas there are only a small number of letters.
 

WesternLancer

Veteran Member
Joined
12 Apr 2019
Messages
15,012
Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.
I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.

It was once a pretty smart hotel - certainly c 10 to 15 years ago when I think I was in there - if from the late 1960s / early 70s concrete block style of architecture.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Yeah I don't mind as long as places are clean. Depending why I'm staying in the hotel, I'm often quite happy to accept a dated interior and a tiny TV in exchange for a lower price.

Problem is the cheaper end almost always compromise on cleanliness. The only time you ever get a tiny basic room but with a good (single) bed, no or a 14" TV etc but spotless and everything working is a family owned hotel. Travelodge for instance always seem to be dirty and in poor repair.

== Doublepost prevention - post automatically merged: ==

I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.

It was once a pretty smart hotel - certainly c 10 to 15 years ago when I think I was in there - if from the late 1960s / early 70s concrete block style of architecture.

I must admit to finding it amusing that people were saying these were 4 star hotels. Maybe once they were. Personally I'd have to be desperate to stay in one even were it free.
 

styles

Established Member
Joined
7 Dec 2014
Messages
4,691
Location
Gwynedd
Problem is the cheaper end almost always compromise on cleanliness. The only time you ever get a tiny basic room but with a good (single) bed, no or a 14" TV etc but spotless and everything working is a family owned hotel. Travelodge for instance always seem to be dirty and in poor repair.
There's a Travelodge I've stayed at for Christmas a week at a time, a few times over the past few years. It is around half the price of any other hotel around, and perfectly clean. The rooms are very basic, but to be honest I come back to the room from spending a day with the family, go straight to sleep, wake up, shower, take dog for walk, and head back over to see the family again. Don't really bother with the TV or WiFi and there's breakfast options nearby if I wanted to buy something.
 

BuhSnarf

Member
Joined
22 May 2010
Messages
754
Location
Leicester
Problem is the cheaper end almost always compromise on cleanliness. The only time you ever get a tiny basic room but with a good (single) bed, no or a 14" TV etc but spotless and everything working is a family owned hotel. Travelodge for instance always seem to be dirty and in poor repair.

Travelodge is SO hit and miss, I've stayed at some dated ones that were clearly well cared for (Saltash) but there are lots that are dated and unclean. The Britannia hotels I've stayed at have had clean rooms, but the rest of the property outside of the reception / ball rooms is often starved for maintenance - but then as the properties are SO big I can see why it takes so long to update everything.

I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.

It was once a pretty smart hotel - certainly c 10 to 15 years ago when I think I was in there - if from the late 1960s / early 70s concrete block style of architecture.

Looks like they've stopped being housing there based on recent news reports - I assume they will get paid some money now by the government to re-do it and then re-open. It may have been good in the past, but it certainly hasn't for many years. I remember staying there in the early 2000s and it felt unsafe but I was very strapped for cash so it did for the night and it's close to Rock City.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Travelodge is SO hit and miss, I've stayed at some dated ones that were clearly well cared for (Saltash) but there are lots that are dated and unclean. The Britannia hotels I've stayed at have had clean rooms, but the rest of the property outside of the reception / ball rooms is often starved for maintenance - but then as the properties are SO big I can see why it takes so long to update everything.

To be fair it isn't just Britannia, I've stayed in similar independent hotels with the same problem for the same reason, e.g. the Royal Kings Arms in Lancaster (now closed). At least Britannia hotels are dirt cheap.
 

The exile

Established Member
Joined
31 Mar 2010
Messages
9,323
Location
Somerset
The problem of course being that most people don't use a secure password.

The wisdom of changing it is, er, changing a bit. My current employer doesn't require that we change them at all. I believe there's now a reckoning that as long as you use enough bits of entropy (i.e. a long password, e.g. a sentence rather than a word) the only need to change it is if you think it may have been breached by way of social engineering, as a brute force attack on a very long password is near impossible.
Probably also a realisation that with multiple systems requiring phenomenally long and meaningless passwords all changing at different times and different intervals people end up writing them down, which rather defeats the object.
 

BuhSnarf

Member
Joined
22 May 2010
Messages
754
Location
Leicester
Probably also a realisation that with multiple systems requiring phenomenally long and meaningless passwords all changing at different times and different intervals people end up writing them down, which rather defeats the object.
Interestingly, a lot of security people have actually swung the other way on having 'password books.' As most attacks now are virtual rather than physically present attacks like the past having an offline password book stored in a locked drawer is actually not as unsafe as it used to be...

It's definitely more preferable than just having the same password for every site.
 

Bletchleyite

Veteran Member
Joined
20 Oct 2014
Messages
113,091
Location
"Marston Vale mafia"
Interestingly, a lot of security people have actually swung the other way on having 'password books.' As most attacks now are virtual rather than physically present attacks like the past having an offline password book stored in a locked drawer is actually not as unsafe as it used to be...

It's definitely more preferable than just having the same password for every site.

It's probably also easier to do if you're writing down sentences which are punctuated and spelled normally. There is very little gained in a long password by replacing A with 4 and S with 5 and the likes. It just makes things less memorable and is so obvious that a brute forcing tool would try it anyway.

A normal sentence about the length of this one that isn't obviously identifiable to the person is about the best you can get.
 

WesternLancer

Veteran Member
Joined
12 Apr 2019
Messages
15,012
Wood - especially for exterior timber work

Whilst wood isn't really a product - when it's processed for sale to make things from I guess it is - and 'modern' wood really isn't, in my view, as good as wood once was - esp if you want to use it for things like window frames, doors, door frames, gates, fencing etc
It seems to rot in the blink of an eye (well not quite but you know what I mean), despite promises of having been treated with all sorts of modern rot inhibitors / preservatives / pressure treatments etc etc prior to sale

This is of course especially applicable to soft wood timber.

I have lived in and maintained or helped maintain 100 to 150 year old houses and where they have original window frames etc - even when made of soft wood, the wood is usually very sound when it comes to things like cyclical preparation for window frame painting etc, even when the paintwork protecting it has got into bad condition.
Modern equivalent frames fitted in houses built over say last 40 - 50 years (or replacement wooden timber work fitted during that period on an older house) is really poor, and the newer it is the worst it seems to be. Significant rot being found or timber work / windows etc needing to be wholly replaced.

I assume this is the prevalence of the growing of strains of 'fast growing' timber with larger proportions of soft white wood that easily rots, despite preservative treatment.

I suppose if i had a need for decent timber it would be well worth finding and reusing old timber from skips when you seen a house being 'renovated' (wrecked?) - in fact it surprises me that such timber doesn't seem to have a reasonable second hand value given its clear record for much better longevity.
 
Joined
21 May 2014
Messages
964
There's a Travelodge I've stayed at for Christmas a week at a time, a few times over the past few years. It is around half the price of any other hotel around, and perfectly clean. The rooms are very basic, but to be honest I come back to the room from spending a day with the family, go straight to sleep, wake up, shower, take dog for walk, and head back over to see the family again. Don't really bother with the TV or WiFi and there's breakfast options nearby if I wanted to buy something.

Travelodge is SO hit and miss, I've stayed at some dated ones that were clearly well cared for (Saltash) but there are lots that are dated and unclean.

I've stayed in my fair share of Travelodges when travelling for gigs, and had come to the conclusion that there are two distinct categories:

1. Conversions - where they've converted an existing building, usually an office block, into a hotel. Generally, these are older, and are a really mixed bag. They can be in good locations, though. Tend to avoid these where possible.

2. Cheap (modular?) new builds - where they've built something from scratch, almost always with a Tesco or similar on the ground floor. These are the ones to look for because they really are all exactly the same and you know what you're getting.

To my horror, I recently discovered a third category on a trip to Liverpool:

3. Someone else's nasty old motel with a Travelodge sign stuck on the front. Avoid at all costs!
 

Top