Live data from Hacker News

A future without passwords

blog.google

41–50 of 227 posts

Re: A future without passwords

#41
post #29

Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…

> companies want to get rid of one of the factors This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow. > So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Unsu…

> in what way is something like a yubikey secured via a password?

It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time).

Re: A future without passwords

#42
post #40

Earlier quoted context omitted.

What is "Google's 2FA" ?

It's the Google Sign In prompts when they moved away from SMS for 2FA [1] [2] [1] https://support.google.com/accounts/answer/7026266 [2] https://www.forbes.com/sites/zakdoffman/2020/06/17/google-co...

Ah, got it thanks.

Re: A future without passwords

#43

Earlier quoted context omitted.

> companies want to get rid of one of the factors This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow. > So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Unsu…

> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabl…

Well, there is a pin on a yubikey[0], but I just meant I don't think it's totally necessary, and I'm not sure exactly when it's required.

> but all of my online/digital properties as well (assuming passwords become a thing of the past)

For sure, and that's definitely not a threat to take lightly - another thing to consider would be when the attacker is someone who inherently has physical access to you (say an abusive partner, parent, etc).

You're totally right that a password can, at least to some extent, help in these situations. Like I said, I still see a use case for the password, it's just that the scope would change - like how password managers only require you to remember one single password, and that password is essentially only used in one place. This really reduces the risk of phishing.

> If they have my phone which has Touch/Face ID enabled, that poses a much more significant challenge to an attacker (and can maybe be mitigated if I can remote wipe the device in time).

Yeah, agreed - I think biometrics can definitely be a key part of how we get to a password-less world. There's other stuff too, like if the attacker has your key, but they're logging in from a new device, maybe it asks for some other verification like a biometric, or even a password / pin - but now the password again is taking a very different, much more limited role.

All I'm really saying is that the current way things work is pretty bad. Passwords get forgotten, guessed, stolen, reused, phished, etc. Using a device solves those problems really well, and while it does have its caveats, I think the caveats are largely addressable.

[0] https://developers.yubico.com/yubikey-piv-manager/PIN_and_Ma...

Re: A future without passwords

#44
Letting Google manage my passwords to Google. Thanks but no thanks. Great fun awaits those who would fall for this and Google later decides to cancel their account for whatever reason their AI will have managed to concoct by then.

Re: A future without passwords

#45
post #33

Earlier quoted context omitted.

No only that anytime you use Google's 2fa, you let them know where you are and what you are doing. Privacy is a commodity we have willingly and unwillingly given up.

What is "Google's 2FA" ?

They have a range of second factor options, including simple SMS to your phone, the use of their authenticator app (which presumably uses TOTP ([1]), and which could therefore be replaced with compatible alternatives, e.g., LastPass's authenticator app), or USB keys containing a second factor (possibly TOTP-based). [2] has an overview of Google's TOTP implementation.

They all do the same basic thing: userid and password let them know who you claim to be, which they validate using one of the second factors listed above.

[1] https://tools.ietf.org/rfc/rfc6238.txt

[2] https://en.wikipedia.org/wiki/Google_Authenticator

Re: A future without passwords

#46
post #24
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

I had a particularly hard time recently due to this when my phone broke and I couldn't replace it for a week or so. It all got figured out in the end, but not being able to access my Google account and all that entails was more of a problem than I expected.

That's why I have the set of printable backup codes in my wallet. One time I forgot my phone, but I had my wallet and was able to log in to my Google account.

Re: A future without passwords

#47
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

I'm with you. I also dislike that I can't even turn this form of 2FA off for my Google account. If I have 2FA enabled, this is required to be one of the methods. The only way to get rid of it is to sign out of my Google account on my phone.

Agree. And worse I sometimes just don’t get the pop ups.

It’s literally the only reason I’m considering dumping the Gmail app. If you use an app password and the standards based mail client like imap or pop, this isn’t forced on you.

Ive also seen an increase in google flagging my accounts for some reason and I have to go and reclaim/verify them using the recovery accounts.

Re: A future without passwords

#48

Earlier quoted context omitted.

What is "Google's 2FA" ?

They have a range of second factor options, including simple SMS to your phone, the use of their authenticator app (which presumably uses TOTP ([1]), and which could therefore be replaced with compatible alternatives, e.g., LastPass's authenticator app), or USB keys containing a second factor (possibly TOTP-based). [2] has an overview of Google's TOTP implementation. They all do the same basic thing: userid and passw…

Yeah I could think of multiple answers to my questions, which is why I asked.

Re: A future without passwords

#49
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not.

To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup codes would stop working, as would any third-party apps that need access to data in your Google account.

The YubiKey, by the way, is a great hardware TOTP key, in addition to being a FIDO U2F key. TOTP has an advantage over U2F in that you can keep backup copies of the TOTP secrets. Of course TOTP is less secure because it is phishable, but U2F is a real pain because you can't make backup copies of the key.

Re: A future without passwords

#50
The thing I like about the password is that it does not involve any additional technology dependencies.

GitHub is going down this road, too, announcing that they will soon disallow password-based auth on git operations.

I'm not sure if I will keep using it after that, because having to log into the website from every workstation, some of which may not even have a browser "good enough" for github.com, is more extra work than I'm willing to attend to.

Post reply on HN