Live data from Hacker News

A future without passwords

blog.google

81–90 of 227 posts

Re: A future without passwords

#81
post #62

Earlier quoted context omitted.

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

docs, drive and photos are pretty packed for me at least

Re: A future without passwords

#82
post #31

Why don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.

There's Firefox Lockwise: http://lockwise.firefox.com Firefox also introduced a feature that offers to generate a secure password when it detects a sign-up page.

Thanks, yes. I'm a firefox user and I had no idea about this. Just goes to show that these kinds of software should be more usable, discoverable.

Re: A future without passwords

#83
I built something like this about 5 yrs ago, applied to YC and they said nope. This is the future, password sucks. The only issue with this is there's still a password in the background and you still have to register. My solution was no signup forms, no passwords. You click one button to sign up to a site, you tap your phone to sign in. This kinda shouldn't belong with Google tho, Google, Facebook wants to use this to keep you to lock you in to their ecosystem. A 3rd party that does only this with absolutely no lock-in is ideal.

Re: A future without passwords

#84

The thing I like about the password is that it does not involve any additional technology dependencies. GitHub is going down this road, too, announcing that they will soon disallow password-based auth on git operations. I'm not sure if I will keep using it after that, because having to log into the website from every workstation, some of which may not even have a browser "good enough" for github.com, is more extra wo…

Can you still use ssh keys? I haven’t used http for git in years. I store the SSH key’s password in the keychain and then I’m good to go.

You can. You can also create tokens that function the exact same as a password but with a customisable scope.

Re: A future without passwords

#85
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

If you don't have a google-enabled android device (as I don't), and you've registered your Yubikey with google (as I have), they won't use the Yubikey they will SMS you instead.

Seems like they prefer google prompt, then SMS, then the actually secure stuff.

Re: A future without passwords

#86

Earlier quoted context omitted.

> companies want to get rid of one of the factors This is because the security of "2FA" isn't really from the fact that there are two factors, but that one of the factors is kinda just ok, and the other factor is ideal. A password on top of a proper 2FA method doesn't actually add any security to the typical login flow. > So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Unsu…

> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabl…

Yubikey is amazing. I only use it on my really important accounts - financial, etc... So I generally don't need it on the road, it stays at home.

I can use biometrics/sms for the less important stuff.

Re: A future without passwords

#88
post #62

Earlier quoted context omitted.

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

> they apparently know how to secure my account better than I do This is definitely true for 99% of people though

And the company is taking full advantage of that.

"Trust us."

Yet no company wants more personal information from you than this one. They want everything. Even when they have so much, they are going to great lengths to get more.

They are not in the security business, they are in the online ad sales business.

Re: A future without passwords

#89
post #62
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

Windows with a Yubikey is like this, most particularly in Edge. It'll accept your key once but you'll have trouble using it again. It'll tell you that it doesn't recognise the key.

Some bullshit with Windows Hello, I'm sure, since using a hardware key in the browser triggers it.

Re: A future without passwords

#90

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

docs, drive and photos are pretty packed for me at least

I was in that same boat, which is why I decided to migrate off gmail and move to a paid provider. One day I just woke up an realized I had to much important shit tied to my email to not be a customer. Paid services to replace google are surprisingly affordable. And best yet, if there is ever an issue, there is also a number I can call. Totally recommend migrating away.
Post reply on HN