Live data from Hacker News

A future without passwords

blog.google

11–20 of 227 posts

Re: A future without passwords

#11
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

I'm with you. I also dislike that I can't even turn this form of 2FA off for my Google account. If I have 2FA enabled, this is required to be one of the methods. The only way to get rid of it is to sign out of my Google account on my phone.

Re: A future without passwords

#13

> Soon we’ll start automatically enrolling users in 2SV if their accounts are appropriately configured I get that this makes accounts more secure, but I'm more worried about accidentally getting locked out because my phone isn't charged/nearby/working than getting phished. I really hate it when sites take your ability to choose away, even though I understand why they do it. I wish the EU would regulate that sites mus…

So when my phone battery is dead and I try to log into my computer to tell everyone I’m going to be late, I can’t message them because my phone battery is dead. Awesome.

Re: A future without passwords

#14
post #9

eggs, meet basket

Turning your $800 personal electronics into the moral equivalent of your physical keychain sounds like a good idea to technologists but it really, really isn’t. I’ve stolen your phone and also can access your bank accounts? Is it my birthday or what? Watches are better this way because you don’t ever set them down (and they’re cheaper), but I suspect pickpockets have some things to say about those magnetic clasps. So…

They're only a PITA to me because my keychain isn't close by. Otherwise, I touch the phone to my keychain and that's it, I'm authenticated. What's painful about that?

Re: A future without passwords

#15
post #8
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

Your laptop (probably) already supports FIDO2 with your TPM, now it's a matter of Google (and others) implementing it.

They have it already in WebAuthn in a completely siloed way. That is, they only implement hardware token support and if you want software tokens, they will make your life painful.

Re: A future without passwords

#16
post #9

Earlier quoted context omitted.

Turning your $800 personal electronics into the moral equivalent of your physical keychain sounds like a good idea to technologists but it really, really isn’t. I’ve stolen your phone and also can access your bank accounts? Is it my birthday or what? Watches are better this way because you don’t ever set them down (and they’re cheaper), but I suspect pickpockets have some things to say about those magnetic clasps. So…

They're only a PITA to me because my keychain isn't close by. Otherwise, I touch the phone to my keychain and that's it, I'm authenticated. What's painful about that?

I have a Yubikey Nano permanently inserted in my Mac. It's always there, at the press of a finger.

Re: A future without passwords

#17
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

I would never want my laptop to be my authentication device for my personal life. I am away from home when I need to log in to things. Even if I'm at home, I am not sitting at my desk when I need to log in.

Re: A future without passwords

#18
post #10

eggs, meet basket

This worries me a lot, just having a dynamic IP in a third world country is enough for Google to lock you out of the account even if you had typed your password correctly. I would never trust them with my access to other sites, one simple mistake of logging in with a different IP and will leave me locked out of all my accounts. In the name of security they ask you to associate a phone number to unlock the account eve…

The dystopian novel practically writes itself.

Imagine being locked out of your house and bank accounts because your Google account got suspended. Maybe Google could introduced an account protection service for people worried about this happening - for a small annual fee of course - and unofficially turn it into racketeering.

Re: A future without passwords

#20
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

Incidentally I was just on the Ebay website and looking through the settings since it's been a while. I thought I'd activate 2FA, but when I saw that they only offer SMS and via their app, I discarded the idea.
Post reply on HN