Live data from Hacker News

A future without passwords

blog.google

21–30 of 227 posts

Re: A future without passwords

#21
post #12

What a nothing-burger article. Just sounds like more lock-in with Google, why is this interesting?

Agreed. This article can be compressed to:

* Google is marginally increasing security by turning on 2FA automatically for some accounts

* Google's password manager has a new "import" feature

Based on the title, I expected maybe some radical new developments in WebAuthn or similar password-replacement technology, not incremental improvements to Google's products that benefit only Google users.

Re: A future without passwords

#22
> We’ve recently launched our new Password Import feature which allows people to easily upload up to 1,000 passwords at a time from various third party sites into our Password Manager (for free).

But the only way to manually add one password is to craft a custom CSV and upload it.

Re: A future without passwords

#23

Earlier quoted context omitted.

They're only a PITA to me because my keychain isn't close by. Otherwise, I touch the phone to my keychain and that's it, I'm authenticated. What's painful about that?

I have a Yubikey Nano permanently inserted in my Mac. It's always there, at the press of a finger.

I have one of those too on my work laptop, it's the most convenient thing ever. Not great if you have multiple computers, but it's great for a single one.

Then again, your Mac already has a TPM chip you can use.

Re: A future without passwords

#24
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

I had a particularly hard time recently due to this when my phone broke and I couldn't replace it for a week or so. It all got figured out in the end, but not being able to access my Google account and all that entails was more of a problem than I expected.

Re: A future without passwords

#25

> Soon we’ll start automatically enrolling users in 2SV if their accounts are appropriately configured I get that this makes accounts more secure, but I'm more worried about accidentally getting locked out because my phone isn't charged/nearby/working than getting phished. I really hate it when sites take your ability to choose away, even though I understand why they do it. I wish the EU would regulate that sites mus…

U2F is obsolete. Greenfield deployments should be of the standard, WebAuthn, instead.

Re: A future without passwords

#26
https://myaccount.google.com/signinoptions/two-step-verifica...

> Google prompts

> "To stop getting prompts on a particular phone, sign out of that phone."

Well, f* you too.

I genuinely hate this idiotic future where I'm not given a choice.

I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Re: A future without passwords

#28
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app?

By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you know, one thing you have, and one thing you are).

Let's imagine we implemented your suggestion of requiring the login to be on a different device than the authenticator app. What threat model does this protect against? An attacker who has your password and the unlocked phone will just sign in from a different device with the password, and then use the authenticator app from the phone. The only people you're protected against are those who do not have any access to another device than the stolen phone.

Re: A future without passwords

#29
Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device, it’s much more painful to deal with. Not sure we’re really making that much progress.
Post reply on HN