A future without passwords
31–40 of 227 posts
Re: A future without passwords
#32What a nothing-burger article. Just sounds like more lock-in with Google, why is this interesting?
"Without passwords" ... by importing your passwords to google! haha
Re: A future without passwords
#33Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…
Re: A future without passwords
#34This post is just marketing.
Re: A future without passwords
#35Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…
This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow.
> So we’re back to one factor that’s ultimately secured by a device password/passcode anyway.
Unsure of exactly what you mean here - in what way is something like a yubikey secured via a password? Also, even if that were the case, changing the scope of passwords is important in and of itself.
> Plus if/when you’re not able to access the device, it’s much more painful to deal with.
Agreed, this is the big problem to solve - essentially this is just a subset of the "recovery" problem. It's one place where passwords may still fit in, though in a different role.
Ultimately, verifying identity at scale is just extremely difficult, and there will never be a perfect solution to recovery, but I think that we can mitigate that quite well with things like:
a) Phones as 2FA devices/ recovery devices
b) Multiple devices (ie: if we can reduce the cost of hardware tokens by an order of magnitude it becomes viable to buy 2+ for many more people)
c) Slower recovery methods that involve leveraging multiple identity methods - things like validating a government issued ID, mailing address, etc.
Re: A future without passwords
#36Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…
No only that anytime you use Google's 2fa, you let them know where you are and what you are doing. Privacy is a commodity we have willingly and unwillingly given up.
Re: A future without passwords
#37She knew the password but they wanted the 2 factor on her registered device. That device was traded in.
That’s ok, the backup plan was to send a code to your phone number on record… of course this fails as well.
It can get very aggravating when 2FA goes the wrong way and people don’t believe you are who you say you are. Assuming that users will always have the same device or the same phone number is an obvious mistake.
Re: A future without passwords
#38Re: A future without passwords
#39I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…
I would never want my laptop to be my authentication device for my personal life. I am away from home when I need to log in to things. Even if I'm at home, I am not sitting at my desk when I need to log in.
Re: A future without passwords
#40Earlier quoted context omitted.
No only that anytime you use Google's 2fa, you let them know where you are and what you are doing. Privacy is a commodity we have willingly and unwillingly given up.
What is "Google's 2FA" ?
[1] https://support.google.com/accounts/answer/7026266 [2] https://www.forbes.com/sites/zakdoffman/2020/06/17/google-co...