Live data from Hacker News

A future without passwords

blog.google

161–170 of 227 posts

Re: A future without passwords

#161
I recently couldn't log in to my Google account on a new device (with a strong password) and the best I got from Google was an email how my login was blocked for security reasons without any indications on how I can say "hey, it was me".

Thank you Google, but I'd rather keep my password than you worry about my logins. You don't know how valuable this account is to me, and what kind of protections I want for it (it's an account I use solely to set up play store on my otherwise de-googled phones).

Re: A future without passwords

#162
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

Some of these authenticator apps store their state in your phones TPM (or "secure enclave") already.

All you're really saying is you want them to ship the authenticator apps to desktop platforms as well as mobile..

Re: A future without passwords

#163
post #5

I’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’…

The worst way is how my bank is currently doing it, they require SMS authentification but do not allow two phones at the same time, and to switch it on you have to sign something and wait for a letter by snail mail.

Now I'm stuck with a decade old phone just to confirm my online transactions, and if it breaks I'm out of luck. The alternative would be to not have working online banking for one or two weeks, which I cannot afford at the moment (thanks to Covid).

Re: A future without passwords

#164

Earlier quoted context omitted.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

what do you use for photos storage ?

As always in this threads I hear people talking about SyncThing etc (and i have it and it's neat) but that works for Android. How do you exit the iCloud land in an easy and reliable way? There is no SyncThing for iOS.

Re: A future without passwords

#165
post #49
post #26

https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

In principle, there is a way for you to have U2F backup keys. Here's a great write-up https://dmitryfrank.com/articles/backup_u2f_token

The basic idea is to have two U2F devices with with the same device_secret but one of the devices (the backup) is pre-programmed to add a large offset to the so called counter value. Upon login the service must check the counter value and ensure that the received value is greater than the one it's seen previously. If you happen to lose the first key, you can use the second key to log into all of the affected online services and upon doing so, the service would accept the new larger counter value and thereby invalidate the lost key.

Re: A future without passwords

#166
post #137
post #97

Earlier quoted context omitted.

I've gone completely off biometric security. It's unchangeable and externally facing. The only truly secure enclave is the things in my head, and they have the benefit of being changeable if compromised, and I can make a positive distinction of value if under duress.

As you should. They are amputationware. [Snark warning!] "We were compromised. Rotate your passwords, chop off your finger and change your face." [End snark] Biometric measurements are fuzzy, by their nature. This in turn means that for every stored biometric identifier, there is a whole range of inputs / input signals that will match. On top of that, the measurement devices are on untrusted systems. If you can compr…

>If you can compromise the device and extract the signal sent from the sensor, you should have a near universal replay payload. Right now that is still an espionage realm threat, but as these methods become more universal, mass attacks against large populations become more and more appealing.

If the manufacturers had a sense of security, they would make the sensor into a hard-wired device that takes an auxiliary value as input and combines the input with a fuzzy extractor to provide a unique key per auxiliary value in such a way that neither the value nor the biometric can be extracted from the key.

But I'm not holding my breath!

Re: A future without passwords

#167
post #141

Earlier quoted context omitted.

The hardest thing for me to replace so far has been Google Maps. I use a handful of OSM map apps, but none of them come close to the local business lookups of Google, which I need quite often.

Right but you don't need an account for that.

You don't need an account for that yet. I've been using Maps in "incognito mode" for 6 months, but I wouldn't be surprised if they're still using Maps to collect data about me.

Re: A future without passwords

#168
post #113
post #72

I want a future without passwords, but that future gives me the choice of third parties to host my passwords. I prefer 1Password, some people like iCloud, while others may prefer a Microsoft solution. Passwords suck and we need a per-site password policy that can act like an API. Kind of like a Robots.txt, to declare, "This site needs 8-20 characters, 1 symbol and the URL's for login, reset and forgot password are th…

Or ditch site passwords and use public key authentication, like ssh has used for decades...

Yes! What could be/are reasons to not do this?

Re: A future without passwords

#169

I don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I fou…

Really can't re-emphasize this enough. Do not depend on any of these large monopolies, but most particularly not google, for anything that matters. They can and will evaporate you in a nanosecond for no reason ("ML says so") and there is no possibility of recourse or even dialogue with any human.

Own your own passwords (don't use "log in with XXX"), own your own domain for email (even if you don't host it, you have the option to do so later instead of being locked out).

Re: A future without passwords

#170
post #62

Earlier quoted context omitted.

>Am I the only person who loathes this form of 2FA? Not in the slightest. I tried to configure TOTP-only and Google effectively tells me to go fuck myself, because they apparently know how to secure my account better than I do.

I've found that if you move away from Gmail (and there are much better providers around), a Google account doesn't contain much. Turn off your history and someone compromising your account can do... what? Search for things you'd like? View your YouTube favorites? Meh.

Better yet, always be logged out of google (and everything else really) unless you must. Then log out and erase all cookies ASAP.
Post reply on HN