Live data from Hacker News

A future without passwords

blog.google

91–100 of 227 posts

Re: A future without passwords

#91
I don't trust Google to fill this role of being arbiter of access to things.

After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I found the secret Konami Code that summoned a human.

That experience was exceedingly frustrating, and has killed the last ounce of trust I have for them to do anything for which I might rely on.

While they have neat technology, if you fall into one of the cracks, it's near impossible to get support.

Re: A future without passwords

#93

The biggest threat is not the password but the recovery email being hacked or google locking out your account if you supply a phone but are unable to verify it after changing your location. That will lock your account. As always google always misdiagnoses the problem which they themselves helped create.

[deleted]

Re: A future without passwords

#94
post #72

I want a future without passwords, but that future gives me the choice of third parties to host my passwords. I prefer 1Password, some people like iCloud, while others may prefer a Microsoft solution. Passwords suck and we need a per-site password policy that can act like an API. Kind of like a Robots.txt, to declare, "This site needs 8-20 characters, 1 symbol and the URL's for login, reset and forgot password are th…

Like these? https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...

1Password (and iCloud Keychain, maybe?) can read these off of the input element and use them when they calculate the password.

Re: A future without passwords

#95

Earlier quoted context omitted.

docs, drive and photos are pretty packed for me at least

I was in that same boat, which is why I decided to migrate off gmail and move to a paid provider. One day I just woke up an realized I had to much important shit tied to my email to not be a customer. Paid services to replace google are surprisingly affordable. And best yet, if there is ever an issue, there is also a number I can call. Totally recommend migrating away.

«there is also a number I can call»

Unfortunately that's a number a hacker can call to social engineer the employee and steal your account. Same method as in SIM swapping attacks.

Re: A future without passwords

#96
post #28
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you k…

I have trouble with the MS signin for work. Looks like blocking third party cookies (which safari seems to do) makes this nearly impossible (or incredibly inconvenient) to use.

Re: A future without passwords

#97
post #29

Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…

> Am I the only one who doesn’t want a future without passwords? As much of a Science Fiction fan I am with "iris logins" and similar, I am also a retro-futurist who appreciates things like punch-number security for secured doors. I mislike this current 2FA path of security for several reasons, the least of which is what if the email never comes or I don't have a cell phone (let alone a smartphone)? I'm screwed. Pass…

I've gone completely off biometric security.

It's unchangeable and externally facing. The only truly secure enclave is the things in my head, and they have the benefit of being changeable if compromised, and I can make a positive distinction of value if under duress.

Re: A future without passwords

#100
post #60

Earlier quoted context omitted.

I was really hoping that would catch on when I got my first yubikey some years ago. So far it seems that basically no one is using it. Which really sucks because it's so much more secure. Makes it impossible to accidentally send credentials to the wrong site.

Same :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.

I've yet to run across one browser / operating system combination where WebAuthn is implemented well. Stuff like assertion interface not showing up if you have two authenticators present. Browser and OS vendors should really fix their shit before any mass WebAuthn adaptation happens.
Post reply on HN