Live data from Hacker News

Let them paste passwords (2017)

ncsc.gov.uk

121–129 of 129 posts

Re: Let them paste passwords (2017)

#121
post #118

Earlier quoted context omitted.

This all sounds very interesting, but doesn’t at all match my lived experience. I’ve dieted now a few times quite successfully while living with a chef roommate. He cooks amazing meals. Salads with more ingredients than I’d ever bother to use, stuff like that. As a chef he really puts time into hitting many flavors (not always, but often). I’ve never had an easier time losing weight than this last time! Down to my he…

> If I eat bland things, sure over time I may adapt to it. I think you're arguing with the GP comment, not my comment. The kind of "diet" being described in my comment above—if you even want to think of it as a diet—doesn't actually stop you from eating anything , if you count by "flavor experiences" rather than "meal experiences." It just makes you get your "flavor experiences" separately, rather than all at the sam…

> They're just different ways of having the same experiences. If you like, you can eat garlic bread for one meal, a Greek salad for the next, and charcuterie for a third—and you'll have "eaten a pizza" of whatever toppings you like.

I'd argue that the simultaneity is a new experience though. Just as playing first the low notes and then the high notes of a musical score sounds radically different than playing both scores at the same time, the taste of pizza is exactly the interaction between cheese flavour, bread and topping.

The theory about satiation sounds plausible and I can easily imagine that you will eat less by consuming only monotonous meals, but I'd disagree stating this would be the same experience are being similarly enjoyable.

Re: Let them paste passwords (2017)

#122

Earlier quoted context omitted.

I don't have the data on sales, so I can't comment on that. Without seeing the marketing, it's hard to tell why OP's solutions are not chosen. (I don't expect it to be as easy as "it's not difficult enough")

Yea, but you could have chosen not to comment at all without detracting from the conversation. If folks around here don’t know what security folks do you have much, much, much larger concerns. Why not engage in good faith? If you can’t do that why comment at all?

Because "security people want to make your life harder" is as meme that needs to die. People actually believe that and if we don't call out that it's wrong and harmful, it will continue to be repeated.

Re: Let them paste passwords (2017)

#123
post #52

Earlier quoted context omitted.

Another unhappy path is very difficult. Your phone got stolen or smashed. Your 2FA is just not available. Welcome to the sea of hassle proving your identity. But a little bit of hassle beforehand, in the form of printing one-time codes and storing them even in your wallet would help dramatically.

Keep the 2fa code sequences safe in a separate keepass or any password database; & you can move 2fa anytime. Even Google updated its Auth app to export all keys.

Wait, when? For iPhone? I just checked and don’t see it.

Re: Let them paste passwords (2017)

#124
post #52

Earlier quoted context omitted.

There was a recent discussion on HN that branches into this idea about the importance of UX. I agree with you, with a twist. What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle. This is the UX I really like for WebAuthn / U2F. All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phon…

Another unhappy path is very difficult. Your phone got stolen or smashed. Your 2FA is just not available. Welcome to the sea of hassle proving your identity. But a little bit of hassle beforehand, in the form of printing one-time codes and storing them even in your wallet would help dramatically.

Just has to abandon a Trello account because of this. They state if you lose your device for TFA you have just lost your account. Okay, bank level security for a PM tool...

Re: Let them paste passwords (2017)

#125

Earlier quoted context omitted.

Keep the 2fa code sequences safe in a separate keepass or any password database; & you can move 2fa anytime. Even Google updated its Auth app to export all keys.

Wait, when? For iPhone? I just checked and don’t see it.

Oh Sorry, I should had been clear; I use Android.

Re: Let them paste passwords (2017)

#126
post #85

Earlier quoted context omitted.

Not necessarily. You could store $10 \choose 5 = 252$ hashes for each user. We did something similar for call center caller authentication (you don't want the operator to get the whole PIN of the user, so he asked only for e.g. two characters). Not that this would be very useful, security-wise.

> Not necessarily. You could store $10 \choose 5 = 252$ hashes for each user. Wouldn't this be way easier to crack if the password hashes were leaked? Once you crack one 5-letter hash, you can trivially crack the one that shares 4 characters with it, and do that repeatedly until you have all 10 characters. You're reducing the effective search space not by a factor of 252 (8 bits of entropy, which would often be accep…

Oh, sure, the authentication itself is fairly usable for the given usecase, the hashing is security theater. I advocated not hashing those PINs, but you know, standards, auditors, etc. "Passwords must be hashed", security theater or not.

Re: Let them paste passwords (2017)

#127
post #118

Earlier quoted context omitted.

This all sounds very interesting, but doesn’t at all match my lived experience. I’ve dieted now a few times quite successfully while living with a chef roommate. He cooks amazing meals. Salads with more ingredients than I’d ever bother to use, stuff like that. As a chef he really puts time into hitting many flavors (not always, but often). I’ve never had an easier time losing weight than this last time! Down to my he…

> If I eat bland things, sure over time I may adapt to it. I think you're arguing with the GP comment, not my comment. The kind of "diet" being described in my comment above—if you even want to think of it as a diet—doesn't actually stop you from eating anything , if you count by "flavor experiences" rather than "meal experiences." It just makes you get your "flavor experiences" separately, rather than all at the sam…

I was explicitly claiming that I think having more variety of flavors and ingredients together makes it easier, so yea it was an example against your theory.

Also your examples fit my experience as well. A hot dog is best with some mustard, relish, maybe grilled onions. The bread has milk, sesame seeds often. The hot dog itself is seasoned with a variety of spices.

Re: Let them paste passwords (2017)

#128

Earlier quoted context omitted.

Yea, but you could have chosen not to comment at all without detracting from the conversation. If folks around here don’t know what security folks do you have much, much, much larger concerns. Why not engage in good faith? If you can’t do that why comment at all?

Because "security people want to make your life harder" is as meme that needs to die. People actually believe that and if we don't call out that it's wrong and harmful, it will continue to be repeated.

Well, it’s also true in many senses. You’re not going to get much of anywhere without recognizing that.

Re: Let them paste passwords (2017)

#129
post #118

Earlier quoted context omitted.

This all sounds very interesting, but doesn’t at all match my lived experience. I’ve dieted now a few times quite successfully while living with a chef roommate. He cooks amazing meals. Salads with more ingredients than I’d ever bother to use, stuff like that. As a chef he really puts time into hitting many flavors (not always, but often). I’ve never had an easier time losing weight than this last time! Down to my he…

> If I eat bland things, sure over time I may adapt to it. I think you're arguing with the GP comment, not my comment. The kind of "diet" being described in my comment above—if you even want to think of it as a diet—doesn't actually stop you from eating anything , if you count by "flavor experiences" rather than "meal experiences." It just makes you get your "flavor experiences" separately, rather than all at the sam…

a) I love that an offhand comment about password entry has spawned a sprawling thread about dieting.

and,

b) This reminds me of Penn Jillette's potato diet, and might explain why it works.

Post reply on HN