Live data from Hacker News

A future without passwords

blog.google

151–160 of 227 posts

Re: A future without passwords

#152
post #141

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

The hardest thing for me to replace so far has been Google Maps. I use a handful of OSM map apps, but none of them come close to the local business lookups of Google, which I need quite often.

Right but you don't need an account for that.

Re: A future without passwords

#153
post #29

Am I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device…

Personally I think the basic building blocks of the password manager workflow is pretty damn close to perfect. Maybe the contemporary password manager could be refined further, but I do like the building blocks: 1. There is an encrypted blob which contains distinct authentication tokens/passwords/whatever for every website/service I have an account at. This blob can be moved around, synced and updated however I like,…

In your system, doesn’t security still just come down to the passcode of your phone and physical access to it? With access to your phone, the attacker will have access to your email, which will likely allow them to reset the password on any account.

Re: A future without passwords

#154

Earlier quoted context omitted.

SMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).

I got 29 hours out of my Pixel last charge.

29 hours is downright disgusting, when compared to feature phones battery life. Some of them have 20-30 days of standby.

Re: A future without passwords

#155
post #28

Earlier quoted context omitted.

> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you k…

The something you know these days is just stored in your password manager, protected by your phone’s passcode most likely, so it all ends up being “something you have”.

Your phone's passcode is something you know.

Re: A future without passwords

#156

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

what do you use for photos storage ?

I have a NAS that backs up to rsync.net.

Re: A future without passwords

#157

Earlier quoted context omitted.

I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.

I really dislike 2FA when it is linked to a phone number. There were so many situations where 2FA made huge troubles to me, e.g. I traveled to Asia before Covid, lost my phone. No problem, it is just hardware, I got a cheap 100 Euro Xiaomi phone around the corner and a local SIM card. But I could not login to my Gmail account to get the booking confirmations + addresses of hotels + flight ticket confirmations. It was…

Multiple yubikeys has been the best option I've found. You can scan the TOTP QR codes into more than one key when you set up 2fa. (Ones with proper key support are even easier to do).

The reason I prefer it is that I don't want to store 2fa credentials on the cloud and I don't want to lose all my codes if I brick my phone. SMS is a poor 2nd factor, so I'd prefer not to rely on it.

There are other issues, no situation is perfect, but I have found hardware keys to be much simpler in the long run.

Re: A future without passwords

#158
post #6
post #4

Am I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety wh…

I would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.

Apple, Google, and Microsoft all support FIDO in their OSes and browsers.

Re: A future without passwords

#159
post #100

Earlier quoted context omitted.

Same :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.

I've yet to run across one browser / operating system combination where WebAuthn is implemented well. Stuff like assertion interface not showing up if you have two authenticators present. Browser and OS vendors should really fix their shit before any mass WebAuthn adaptation happens.

What don't you like about the Win10 + Edge implementation?

Re: A future without passwords

#160

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

what do you use for photos storage ?

I use Wasabi with Clouberry for backups and otherwise store all data on my hard disks.

But if you're into "cloud" storage, Mega.nz gives you 50GB of free and very reliable storage.

Post reply on HN