Live data from Hacker News

A future without passwords

blog.google

111–120 of 227 posts

Re: A future without passwords

#111
post #73

Earlier quoted context omitted.

SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.

SMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).

I got 29 hours out of my Pixel last charge.

Re: A future without passwords

#112
post #62

Earlier quoted context omitted.

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

what do you use for photos storage ?

Re: A future without passwords

#113
post #72

I want a future without passwords, but that future gives me the choice of third parties to host my passwords. I prefer 1Password, some people like iCloud, while others may prefer a Microsoft solution. Passwords suck and we need a per-site password policy that can act like an API. Kind of like a Robots.txt, to declare, "This site needs 8-20 characters, 1 symbol and the URL's for login, reset and forgot password are th…

Or ditch site passwords and use public key authentication, like ssh has used for decades...

Re: A future without passwords

#114
post #73

I don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a second factor to my password, and then trust the IP on user decision. Please don't make me use a smartphone app.

SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.

I hear this all the time, but you’re sooo unlikely to be important enough for this to actually matter. And even if it did happen, the attacker would still need your password (and sometimes your phone number) first.

Re: A future without passwords

#115
post #29

Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…

If one of the factors is extremely secure (pushes, smartcard FIDO2, yubikey) then I think it is reasonable for the other factor to just be a PIN instead of a password.

Re: A future without passwords

#116

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

what do you use for photos storage ?

Not OP. While I've personally not yet fully migrated out of Google, I found Synching and Resilio Sync quite useful to transparently backup photos to my own computer. And to prevent losses, I have a Backblaze subscription.

While I do have a VPS, it only has like 20GB, so I've yet to find an affordable and easy photo sharing solution.

Re: A future without passwords

#117
post #107
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

You can use regular TOTP with Microsoft. You have to click some box during setup that will show you a QR Code. I can't remember what it said, but I did it a few months ago after a tip here on HN.

https://authy.com/wp-content/uploads/2018-07-27_1450.png

Re: A future without passwords

#118

I don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I fou…

I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.

Re: A future without passwords

#119
post #60

Earlier quoted context omitted.

I was really hoping that would catch on when I got my first yubikey some years ago. So far it seems that basically no one is using it. Which really sucks because it's so much more secure. Makes it impossible to accidentally send credentials to the wrong site.

Same :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.

With Safari now having it built-in so you can do FaceID/TouchID I have a feeling it is about to become more common for websites.
Post reply on HN