Earlier quoted context omitted.
SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.
SMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).
A future without passwords
111–120 of 227 posts
Re: A future without passwords
#112Earlier quoted context omitted.
>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.
I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.
Re: A future without passwords
#113I want a future without passwords, but that future gives me the choice of third parties to host my passwords. I prefer 1Password, some people like iCloud, while others may prefer a Microsoft solution. Passwords suck and we need a per-site password policy that can act like an API. Kind of like a Robots.txt, to declare, "This site needs 8-20 characters, 1 symbol and the URL's for login, reset and forgot password are th…
Re: A future without passwords
#114I don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a second factor to my password, and then trust the IP on user decision. Please don't make me use a smartphone app.
SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.
Re: A future without passwords
#115Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…
Re: A future without passwords
#116Earlier quoted context omitted.
I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.
what do you use for photos storage ?
While I do have a VPS, it only has like 20GB, so I've yet to find an affordable and easy photo sharing solution.
Re: A future without passwords
#117Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…
You can use regular TOTP with Microsoft. You have to click some box during setup that will show you a QR Code. I can't remember what it said, but I did it a few months ago after a tip here on HN.
Re: A future without passwords
#118I don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I fou…
Re: A future without passwords
#119Earlier quoted context omitted.
I was really hoping that would catch on when I got my first yubikey some years ago. So far it seems that basically no one is using it. Which really sucks because it's so much more secure. Makes it impossible to accidentally send credentials to the wrong site.
Same :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.