Live data from Hacker News

A future without passwords

blog.google

101–110 of 227 posts

Re: A future without passwords

#102
post #49
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

Impossibility of U2F key cloning is a security feature. As a backup you use another keys, registered in the same service.

Re: A future without passwords

#103
post #77

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

Agreed. I have moved off of Gmail (went to fastmail, very happy) and I also removed my other services off of my gmail account for logins. My google account has my calendar and youtube and that’s it.

Me too! However, my fastmail app is slow on my phone (a Nokia 6.1), compared to the Gmail app which, while not buttery smooth, is still faster than Fastmail...

And the Gmail app refuses to allow IMAP accounts to archive emails, so that's pointless...

Re: A future without passwords

#104
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

A well-designed MFA system has multiple fall backs available. Google's has options to fall back to sending an SMS (not the highest level of security, but security is always a trade-off), so if you're phone's broken you can move the SIM to another one. Or a phone call to a pre-registered landline that will read out a code to you. As well as the paper/printable emergency codes. That said, there's always going to be com…

Google also has a TOTP fallback, which solves the "I want my second factor to be my laptop" perfectly.

Re: A future without passwords

#105

My sister was divorced and had to split her phone off from the shared plan. Not wanting to bother her ex, she just changed her number and got a new phone. A week or so later she tried to sign into Amazon: She knew the password but they wanted the 2 factor on her registered device. That device was traded in. That’s ok, the backup plan was to send a code to your phone number on record… of course this fails as well. It…

Amazon is a pretty bad example because it does give you backup codes to override 2SV. But for most properly implemented sites, if your sister had the backup codes, that issue shouldn't happen.

I doubt that most people keep the backup codes.

Re: A future without passwords

#106
post #49
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

> It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not

Don't you have a second authentication factor to login on your phone? Fingerprint, pin, faceId.

I don't see how this is worse than a yubikey.

Re: A future without passwords

#107
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

You can use regular TOTP with Microsoft. You have to click some box during setup that will show you a QR Code. I can't remember what it said, but I did it a few months ago after a tip here on HN.

Re: A future without passwords

#108

I don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I fou…

Pretty much what happened to an email address of mine. I'm migrating away from google.

Re: A future without passwords

#109
post #49
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

> but U2F is a real pain because you can't make backup copies of the key.

The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys.

Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.

Re: A future without passwords

#110
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

Every time I log in, ebay bugs me to confirm my phone number "for security purposes". I say no, because I know the next step is harassing me with text messages every time I want to log in (like Google, etc). Passwords work for many of us. I generate them with pwgen(1), store them in a text file on encfs, and cache them in browsers. If my actual desktop computer ever got pwnt, I would have much bigger problems than a Gmail account or even online banking. This might not match the security model of people who reuse passwords across sites, and/or log into accounts on public computers (derp), but it is the original security model of the web and it's extremely frustrating that companies are attempting to destroy it in favor of some magic (read: unpredictable) new system that continually gets in your way.
Post reply on HN