Live data from Hacker News

A future without passwords

blog.google

1–10 of 227 posts

Re: A future without passwords

#4
Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me!

My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? I'm basically alt-tab'ing and clicking a different button, not really an improvement. It should be on a separate device, or something out of Microsoft's control so they can't screw it up.

Worse still is SMS 2FA, which appears to just be an analytics technique rather than a security feature. As we know, a phone number is only as secure as a carrier's most-tired employee.

Re: A future without passwords

#5
I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in.

I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’s Touch Bar where there is a separate integrated physical device with a screen that can make security prompts is ideal.

Re: A future without passwords

#6
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.

Re: A future without passwords

#7
> Soon we’ll start automatically enrolling users in 2SV if their accounts are appropriately configured

I get that this makes accounts more secure, but I'm more worried about accidentally getting locked out because my phone isn't charged/nearby/working than getting phished. I really hate it when sites take your ability to choose away, even though I understand why they do it.

I wish the EU would regulate that sites must implement U2F (with proper support for multiple keys) so at least you don't have to deal with 100 different (and usually annoying) 2FA methods (often the insecure SMS 2FA).

Re: A future without passwords

#8
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

Your laptop (probably) already supports FIDO2 with your TPM, now it's a matter of Google (and others) implementing it.

Re: A future without passwords

#9

eggs, meet basket

Turning your $800 personal electronics into the moral equivalent of your physical keychain sounds like a good idea to technologists but it really, really isn’t. I’ve stolen your phone and also can access your bank accounts? Is it my birthday or what?

Watches are better this way because you don’t ever set them down (and they’re cheaper), but I suspect pickpockets have some things to say about those magnetic clasps.

Something in your wallet or with your keys would be best but then you can’t interact with it easily. Those little physical security tokens you’d put on your keychain were always a PITA.

Re: A future without passwords

#10

eggs, meet basket

This worries me a lot, just having a dynamic IP in a third world country is enough for Google to lock you out of the account even if you had typed your password correctly. I would never trust them with my access to other sites, one simple mistake of logging in with a different IP and will leave me locked out of all my accounts. In the name of security they ask you to associate a phone number to unlock the account even though that makes little sense since anyone with the password can then provide any number and steal the account.
Post reply on HN