Live data from Hacker News

A future without passwords

blog.google

211–220 of 227 posts

Re: A future without passwords

#211
post #73

Earlier quoted context omitted.

SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.

SMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).

Neither does TOTP? There are plenty of desktop applications that support it. I personally use Keepass.

Re: A future without passwords

#212
post #73

Earlier quoted context omitted.

SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.

I hear this all the time, but you’re sooo unlikely to be important enough for this to actually matter. And even if it did happen, the attacker would still need your password (and sometimes your phone number) first.

Ok. It's still a good reason for companies to not support SMS 2FA. Email 2FA or TOTP are miles better.

Re: A future without passwords

#213
post #73

Earlier quoted context omitted.

SMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.

SMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).

Well TOTP is absolutely trivial and there's no reason a non-smart phone couldn't or shouldn't have support for it too.

Re: A future without passwords

#214
Can my government simply issue me a card that looks like this, https://en.wikipedia.org/wiki/Estonian_identity_card, wherein one side has an official ID chip and the other side has a user-managed chip for solvent identity? Then, we can all stop mucking about with this or trying to hock something.

Re: A future without passwords

#215

Earlier quoted context omitted.

I had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.

I really dislike 2FA when it is linked to a phone number. There were so many situations where 2FA made huge troubles to me, e.g. I traveled to Asia before Covid, lost my phone. No problem, it is just hardware, I got a cheap 100 Euro Xiaomi phone around the corner and a local SIM card. But I could not login to my Gmail account to get the booking confirmations + addresses of hotels + flight ticket confirmations. It was…

I found pass with the otp extension to be pretty good, I can sync it with git and get the codes from any of my devices.

pass: https://www.passwordstore.org/

otp extension: https://github.com/tadfisher/pass-otp

Re: A future without passwords

#216
post #49

Earlier quoted context omitted.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

Impossibility of U2F key cloning is a security feature. As a backup you use another keys, registered in the same service.

Sure, not being clonable is a security feature, but it's a huge pain to keep multiple keys registered on all of your services.

For real backup resiliency, you should have at least 3 keys, one of which you keep off-site. Presumably you keep one at home and one with you. Want to sign up for a new service? I hope you're at home where you can access two of your keys to register them. Then sometime later you need to go to your off-site location to swap that key, bring it home, and get it registered also. Do that periodically so all of your services are on all 3 keys.

Unclonable hardware keys work well enough when it's for a corporate service. Lose the key? Just visit IT and have them give you a new one or overnight it. But unclonable hardware keys are a huge pain when used personally with multiple services.

TOTP secrets, while less secure, are much easier to manage. You can write them down, store them on a USB stick, or store them in an online account. You can send them in a message or even read them over the phone. Ultimately the average user is more concerned about losing access to their account than being attacked by a nation state.

Re: A future without passwords

#217
post #109
post #49

Earlier quoted context omitted.

Google has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup c…

> but U2F is a real pain because you can't make backup copies of the key. The backup is to have multiple U2F keys. I have over 10 U2F keys. Most (but not all) providers allow you to register multiple U2F keys. Amazon AWS for some foolish reason (in my opinion) is one of those outliers which only allows one U2F keys to be registered. I've read people's reasoning on why that is and none of it makes sense to me.

And what a pain it is to keep multiple keys registered on all of your services. At least one of those keys should be stored off-site, which means making trips to the off-site location to swap that key, bring it home, and get it registered also. Do that again when you want to register a new service.

Re: A future without passwords

#219

Earlier quoted context omitted.

I got 29 hours out of my Pixel last charge.

29 hours is downright disgusting, when compared to feature phones battery life. Some of them have 20-30 days of standby.

7 hours of that was Hotspot WiFi to two laptops in the park and playing tunes.

shrugs

Re: A future without passwords

#220

Earlier quoted context omitted.

I'm currently in a similar situation. Got an email domain snatched from me when it expired without me noticing, and now Google won't even go through the account recovery steps, just keeps sending emails to an address that no longer exists. I swear having a human contact would resolve this in absolutely no time, but that's just not how Google works.

This never ending stream of stories got me thinking that Google leads the world towards a technocratic dystopian society, where all of us live in the mercy of faceless, reasonless pieces of software.

Have you seen the movie Brazil?
Post reply on HN