Earlier quoted context omitted.
> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you k…
GP is saying they're using an authenticator running on the computer they're logging in on (they alt-tab to it from the browser). So they have two factors in the sense of "something you know" vs. "something you have" but in this case the something they have is the same device.
A future without passwords
181–190 of 227 posts
Re: A future without passwords
#182Earlier quoted context omitted.
I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.
I'm currently in a similar situation. Got an email domain snatched from me when it expired without me noticing, and now Google won't even go through the account recovery steps, just keeps sending emails to an address that no longer exists. I swear having a human contact would resolve this in absolutely no time, but that's just not how Google works.
Re: A future without passwords
#183Earlier quoted context omitted.
> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabl…
Yubikey is amazing. I only use it on my really important accounts - financial, etc... So I generally don't need it on the road, it stays at home. I can use biometrics/sms for the less important stuff.
Re: A future without passwords
#184Earlier quoted context omitted.
Not everyone has a SIM to begin with. Or it is lost with the phone. Anything that has a single or dual point of failure is dead on arrival. Too bad you will realize only after you are locked out of all your digital life.
Authentication always has a single point of failure: you. If other people could log in as you it would defeat the point
Re: A future without passwords
#185Why don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.
Good password managers are a dime a dozen.
Re: A future without passwords
#186Earlier quoted context omitted.
Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…
> It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not Don't you have a second authentication factor to login on your phone? Fingerprint, pin, faceId. I don't see how this is worse than a yubikey.
Re: A future without passwords
#187Earlier quoted context omitted.
> but U2F is a real pain because you can't make backup copies of the key. The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys. Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.
> I have over 10 U2F keys. Can you walk me through your workflow with these? Are some stored offsite? Do you have to gather all your keys together when you are signing up for a new service with U2F support?
I have 4 main ones that I try to keep synced with every service. Though I usually try to sync up a few more if I have them handy.
For me those four are:
Laptop (Yubikey 5C Nano) Desktop #1 (Youbikey 5 Nano) Desktop #2 (Yubikey 4 Nano) Keychain (Yubikey 5 NFC)
I also have one in my work-laptop but it is only registered for work related sites. I also register some of the previously mentioned ones for my work related sites as a backup.
Re: A future without passwords
#188Earlier quoted context omitted.
Every time I log in, ebay bugs me to confirm my phone number "for security purposes". I say no, because I know the next step is harassing me with text messages every time I want to log in (like Google, etc). Passwords work for many of us. I generate them with pwgen(1), store them in a text file on encfs, and cache them in browsers. If my actual desktop computer ever got pwnt, I would have much bigger problems than a…
eBay would not flip on two factor without you knowing. Likely it is to alert you of a new device accessing your account and possibly part of a password reset flow. It’s a good point though — how munch more secure is two factor if you have an unguessable password locked away in a password manager. Your single point of failure is security of your computer.
And yeah I do get the idea that if my password is actually compromised and hostilely changed, I'm going to be looking at the company for some sort of reset. But the right way of doing this is a higher friction process that could require phone engagement, in person notarization, etc. It's certainly not to make this reset process part of the every day login experience based on this mistaken idea that passwords are always insecure.
Re: A future without passwords
#189Earlier quoted context omitted.
what do you use for photos storage ?
As always in this threads I hear people talking about SyncThing etc (and i have it and it's neat) but that works for Android. How do you exit the iCloud land in an easy and reliable way? There is no SyncThing for iOS.