Live data from Hacker News

A future without passwords

blog.google

61–70 of 227 posts

Re: A future without passwords

#61
post #57

In a "future without passwords" every signle web site will use their own app for 2FA, forcing you to install all of them. It should be possible to have one common open standard for "push" 2FA apps and let consumer chose which app to use. Like we have now with Google Authenticator, andOTP, DuoMobile, etc, but with unified "push" functionality.

Or we can use WebAuthn.

Re: A future without passwords

#62
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

>Am I the only person who loathes this form of 2FA?

Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

Re: A future without passwords

#63
post #60
post #6

Earlier quoted context omitted.

I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.

I was really hoping that would catch on when I got my first yubikey some years ago. So far it seems that basically no one is using it. Which really sucks because it's so much more secure. Makes it impossible to accidentally send credentials to the wrong site.

Same :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.

Re: A future without passwords

#64

My sister was divorced and had to split her phone off from the shared plan. Not wanting to bother her ex, she just changed her number and got a new phone. A week or so later she tried to sign into Amazon: She knew the password but they wanted the 2 factor on her registered device. That device was traded in. That’s ok, the backup plan was to send a code to your phone number on record… of course this fails as well. It…

Amazon is a pretty bad example because it does give you backup codes to override 2SV. But for most properly implemented sites, if your sister had the backup codes, that issue shouldn't happen.

Re: A future without passwords

#65
post #62
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

Re: A future without passwords

#66
post #31

Why don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.

You can do this with the new version of Edge: https://support.microsoft.com/en-us/topic/use-password-gener... And https://docs.microsoft.com/en-us/deployedge/microsoft-edge-s...

Re: A future without passwords

#67
post #6
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.

IIRC, the Google/Android 2FV implements FIDO2

Re: A future without passwords

#68

I don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a second factor to my password, and then trust the IP on user decision. Please don't make me use a smartphone app.

[deleted]

Re: A future without passwords

#69
post #62
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

> they apparently know how to secure my account better than I do

This is definitely true for 99% of people though

Re: A future without passwords

#70
post #6

Earlier quoted context omitted.

I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.

IIRC, the Google/Android 2FV implements FIDO2

Isn't it U2F?
Post reply on HN