Live data from Hacker News

A future without passwords

blog.google

181–190 of 227 posts

Re: A future without passwords

#181
post #28

Earlier quoted context omitted.

> But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? By ensuring that whoever signs into the account has at least two distinct factors: the password and the trusted phone with the authenticator app. One thing you know, one thing you have. Perfect. (Depending on your phone's settings around biometric unlock, it might be even the trifecta: one thing you k…

GP is saying they're using an authenticator running on the computer they're logging in on (they alt-tab to it from the browser). So they have two factors in the sense of "something you know" vs. "something you have" but in this case the something they have is the same device.

Yes, I understand that. And like I explained, there is nothing wrong with it being the same device.

Re: A future without passwords

#182

Earlier quoted context omitted.

I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.

I'm currently in a similar situation. Got an email domain snatched from me when it expired without me noticing, and now Google won't even go through the account recovery steps, just keeps sending emails to an address that no longer exists. I swear having a human contact would resolve this in absolutely no time, but that's just not how Google works.

This never ending stream of stories got me thinking that Google leads the world towards a technocratic dystopian society, where all of us live in the mercy of faceless, reasonless pieces of software.

Re: A future without passwords

#183

Earlier quoted context omitted.

> in what way is something like a yubikey secured via a password? It isn't, which makes me confused about how it is supposed to be more secure. If I lose my keys with a physical security key attached, not only do I now have to worry about somebody breaking into my house, but all of my online/digital properties as well (assuming passwords become a thing of the past). If they have my phone which has Touch/Face ID enabl…

Yubikey is amazing. I only use it on my really important accounts - financial, etc... So I generally don't need it on the road, it stays at home. I can use biometrics/sms for the less important stuff.

Which financial institutions use YubiKeys? I didn't think there were any. https://www.dongleauth.info/ doesn't have any banks that do.

Re: A future without passwords

#184
post #129

Earlier quoted context omitted.

Not everyone has a SIM to begin with. Or it is lost with the phone. Anything that has a single or dual point of failure is dead on arrival. Too bad you will realize only after you are locked out of all your digital life.

Authentication always has a single point of failure: you. If other people could log in as you it would defeat the point

That is at least within my control, I can live with that.

Re: A future without passwords

#185
post #171
post #31

Why don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.

Good password managers are a dime a dozen.

Sure, but why aren't people using them? There's a disconnect between implementation and usage.

Re: A future without passwords

#186
post #49

Earlier quoted context omitted.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

> It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not Don't you have a second authentication factor to login on your phone? Fingerprint, pin, faceId. I don't see how this is worse than a yubikey.

Hardware key is offline device, phones are online devices. While phones might have arguably quite good security, their attack surface is many times bigger than offline device that you keep with you. There is almost no way for remote attacker to gain access to offline device (though local attacker will likely have easier time getting that than phone). With phone it comes more down to cost/luck (pay/develop 0days until you have full chain).

Re: A future without passwords

#187
post #109

Earlier quoted context omitted.

> but U2F is a real pain because you can't make backup copies of the key. The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys. Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.

> I have over 10 U2F keys. Can you walk me through your workflow with these? Are some stored offsite? Do you have to gather all your keys together when you are signing up for a new service with U2F support?

I do have over 10 U2F keys. Do I make sure every single one is synced with every service? No.

I have 4 main ones that I try to keep synced with every service. Though I usually try to sync up a few more if I have them handy.

For me those four are:

Laptop (Yubikey 5C Nano) Desktop #1 (Youbikey 5 Nano) Desktop #2 (Yubikey 4 Nano) Keychain (Yubikey 5 NFC)

I also have one in my work-laptop but it is only registered for work related sites. I also register some of the previously mentioned ones for my work related sites as a backup.

Re: A future without passwords

#188

Earlier quoted context omitted.

Every time I log in, ebay bugs me to confirm my phone number "for security purposes". I say no, because I know the next step is harassing me with text messages every time I want to log in (like Google, etc). Passwords work for many of us. I generate them with pwgen(1), store them in a text file on encfs, and cache them in browsers. If my actual desktop computer ever got pwnt, I would have much bigger problems than a…

eBay would not flip on two factor without you knowing. Likely it is to alert you of a new device accessing your account and possibly part of a password reset flow. It’s a good point though — how munch more secure is two factor if you have an unguessable password locked away in a password manager. Your single point of failure is security of your computer.

But this is exactly what Google did to me - rejected using my perfectly good password in favor of "two factor" authentication consisting of my recovery email and some saved browser session (which no longer exists as I periodically wipe browser sessions). Plus the countless number of websites (usually online banking) that abuse your phone/email to send you a code for every login, having been spoiled by the mobile-surveillance environment. So I really can't trust that eBay wouldn't start doing something similar.

And yeah I do get the idea that if my password is actually compromised and hostilely changed, I'm going to be looking at the company for some sort of reset. But the right way of doing this is a higher friction process that could require phone engagement, in person notarization, etc. It's certainly not to make this reset process part of the every day login experience based on this mistaken idea that passwords are always insecure.

Re: A future without passwords

#189

Earlier quoted context omitted.

what do you use for photos storage ?

As always in this threads I hear people talking about SyncThing etc (and i have it and it's neat) but that works for Android. How do you exit the iCloud land in an easy and reliable way? There is no SyncThing for iOS.

I wish SyncThing was more userfriendly or something. I've tried it on different Android phones and computers and have never gotten it to work.
Post reply on HN