Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…
I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.
A future without passwords
131–140 of 227 posts
Re: A future without passwords
#132Earlier quoted context omitted.
A well-designed MFA system has multiple fall backs available. Google's has options to fall back to sending an SMS (not the highest level of security, but security is always a trade-off), so if you're phone's broken you can move the SIM to another one. Or a phone call to a pre-registered landline that will read out a code to you. As well as the paper/printable emergency codes. That said, there's always going to be com…
Not everyone has a SIM to begin with. Or it is lost with the phone. Anything that has a single or dual point of failure is dead on arrival. Too bad you will realize only after you are locked out of all your digital life.
If other people could log in as you it would defeat the point
Re: A future without passwords
#133In particular, the only two threats that 2FA as widely implemented on websites protect against are password reuse, and weak passwords. Both are the results of users choosing stupid passwords.
Re: A future without passwords
#134As someone whose main project surrounds passwords, I could appreciate a future without passwords, because I consider most existing solutions to be quite poor. However, this feels more like having your sheep be herded by a fox... Many here have already mentioned great points retorting this, so I won't beat a dead horse. I will take the selfish opportunity to mention what my solution is that I'm working on: https://app…
The key element that didn't make your list is phishing. The next threat to Joe Average once he isn't reusing a crap password is phishing. Joe goes to a site which he thinks is the right place but it isn't, it's actually run by bad guys and then Joe gives them his credentials and helps them break into the real site Joe thought he was visiting.
Better passwords make no difference to that. Some types of password managers might slow Joe down a bit, as he needs to override a default presumption that this is the wrong site, but since the site has tricked Joe already this is very fragile. TOTP makes no difference, SMS of course makes no difference, and even the Google Auth tech AFAIK makes no difference.
But WebAuthn just stops this attack dead in its tracks.
Re: A future without passwords
#135Earlier quoted context omitted.
I was in that same boat, which is why I decided to migrate off gmail and move to a paid provider. One day I just woke up an realized I had to much important shit tied to my email to not be a customer. Paid services to replace google are surprisingly affordable. And best yet, if there is ever an issue, there is also a number I can call. Totally recommend migrating away.
« there is also a number I can call » Unfortunately that's a number a hacker can call to social engineer the employee and steal your account. Same method as in SIM swapping attacks.
1.) Some unexpected glitch occurs (could be the user's fault or could be the company's), and the user's ability to access the service is temporarily interrupted until a human is able to investigate and resolve the problem.
2.) The user is specifically targeted by a malicious actor performing SIM swap and/or social engineering attack.
I'm not really a gambler, but if I'm forced to guess, I'd say #1.
EDIT: clarify initial assumptions
Re: A future without passwords
#136Somewhat controversial opinion: The biggest problem with passwords is that users select them, and users are stupid. We would get 95% of the benefit of 2FA (For forms of 2FA that aren't yubikeys, as yubikeys have benefits related to phising, but nobody uses them so its moot) if websites chose passwords for users instead of the user choosing the password. In particular, the only two threats that 2FA as widely implement…
Re: A future without passwords
#137Earlier quoted context omitted.
> Am I the only one who doesn’t want a future without passwords? As much of a Science Fiction fan I am with "iris logins" and similar, I am also a retro-futurist who appreciates things like punch-number security for secured doors. I mislike this current 2FA path of security for several reasons, the least of which is what if the email never comes or I don't have a cell phone (let alone a smartphone)? I'm screwed. Pass…
I've gone completely off biometric security. It's unchangeable and externally facing. The only truly secure enclave is the things in my head, and they have the benefit of being changeable if compromised, and I can make a positive distinction of value if under duress.
[Snark warning!]
"We were compromised. Rotate your passwords, chop off your finger and change your face."
[End snark]
Biometric measurements are fuzzy, by their nature. This in turn means that for every stored biometric identifier, there is a whole range of inputs / input signals that will match. On top of that, the measurement devices are on untrusted systems.
If you can compromise the device and extract the signal sent from the sensor, you should have a near universal replay payload. Right now that is still an espionage realm threat, but as these methods become more universal, mass attacks against large populations become more and more appealing.
Archives of valid (username, password) tuples are already sold on underground markets. It's not much of a stretch to predict that (username, biometric sensor dump) archives will eventually become a commodity too.
Re: A future without passwords
#138Earlier quoted context omitted.
Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…
> but U2F is a real pain because you can't make backup copies of the key. The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys. Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.
Can you walk me through your workflow with these? Are some stored offsite? Do you have to gather all your keys together when you are signing up for a new service with U2F support?
Re: A future without passwords
#139I don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I fou…
I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.
Apple forces me to instal 2FA, but I just don't want. I cannot use a third party app or tool but must use my phone number. This is pure pain to me, because I want to use things like Apple Cash or AirPlay from the phone to the AppleTV.
Is there a better solution? I dont know. But 2FA, especially when linked to a phone number, is terrible - at least from my usability point of view.
Re: A future without passwords
#140Earlier quoted context omitted.
A well-designed MFA system has multiple fall backs available. Google's has options to fall back to sending an SMS (not the highest level of security, but security is always a trade-off), so if you're phone's broken you can move the SIM to another one. Or a phone call to a pre-registered landline that will read out a code to you. As well as the paper/printable emergency codes. That said, there's always going to be com…
Not everyone has a SIM to begin with. Or it is lost with the phone. Anything that has a single or dual point of failure is dead on arrival. Too bad you will realize only after you are locked out of all your digital life.
This compares very favourably to, say, AWS where you can only have a single second factor and the recommended(!) way of protecting against loss of a second factor is to have multiple accounts with different second factors registered to each of them.