Live data from Hacker News

The New Ten-Factor Authentication Processes

mcsweeneys.net

31–40 of 107 posts

Re: The New Ten-Factor Authentication Processes

#32
the problem with mcsweeneys is that it's a humor publication that fails at humor. it's like those sitcoms from the 80s where they had to add laugh tracks because no one actually laughed while watching them. at best it's something for young adults to forward around to try and look sophisticated, but like those young adults, it misses the point entirely by trying much too hard.

Re: The New Ten-Factor Authentication Processes

#33

My grandparents recently got locked out of their Comcast account the other day. They forced multi-factor on all their customers in the last year. You could not imagine how hard it is to have the internet without also having a cell phone. Modern security is a usability nightmare.

  s/s(ec)uri(t)(y)/\2\1hnolog\3/
FTFY

Re: The New Ten-Factor Authentication Processes

#34
post #22
post #11

Earlier quoted context omitted.

I'm one of your technical brethren, and non-technical people aren't the only ones who think 2FA is a pain. Don't get me wrong, the security benefits are worth it. But having to pull out my phone multiple times a day to enter a code from an authenticator app? Dude, my phone communicates with my laptop throughout the day. Why does this need me in the mix? Digital OTP, like the kind provided by 1Password or Bitwarden, a…

I remember a DevOps engineer at my last job telling me about a "cheat code" where we could type 'push' into the VPN 2FA prompt to have it pushed as a notification to the enrolled device. I've been typing the same command into every 2FA prompt I encounter since then with no luck. I wish that was a standard convention.

There shouldn't be a standard convention for a "cheat code" - if the thing can do push, it just should offer it in the UI.

Re: The New Ten-Factor Authentication Processes

#35

Earlier quoted context omitted.

How about you allow me to turn off the second factor if I have a password manager, because I'm way more concerned about loosing my second factor and getting locked out of my account than someone somehow getting into my password manager.

I personally use 1password for authenticator codes - highly recommend if you haven't seen it: https://support.1password.com/one-time-passwords/ Edit: Didn't answer the actual question - it's something we can look into. My instinct is that offering this wouldn't drastically change the security model, as long as we can be confident your password actually came from a secure password manager. Since some password managers…

But doesn't this completely defeat the purpose of the codes, since they're no longer a second factor? I'd rather just not have the codes, as they're still a significant annoyance with next to zero benefit.

Re: The New Ten-Factor Authentication Processes

#36

My grandparents recently got locked out of their Comcast account the other day. They forced multi-factor on all their customers in the last year. You could not imagine how hard it is to have the internet without also having a cell phone. Modern security is a usability nightmare.

Plus, grandparents, the group notorious for their tech-skill.

I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

Re: The New Ten-Factor Authentication Processes

#37
post #14

Here's a question spurred by the post. Who administers and issues VINs? I assume VINs are the same throughout the world. Is there some sort of worldwide regulatory body, or is compliance by manufacturers simply a gentlemens' agreement?

Before 1981 car manufacturers just made up their own numbers. Now there’s a global SAE standard.

The NHTSA in the United States has a partnership with SAE.

Re: The New Ten-Factor Authentication Processes

#39

A sign of the times. Seems like our non-technical brethren find 2FA/MFA a burden? McSweeneys’ satire and parodies are rarely in good jest in my experience. This is a criticism of the move towards 2FA/MFA make no doubt about it. The writer, and the editors who let this through, are not happy about this state of affairs. McSweeney’s isn’t a no-name blog or journal either — its name holds sway over those who work in lit…

They seem to be in good jest much more than rarely to me: https://www.mcsweeneys.net/articles/oh-my-fucking-god-get-th... https://www.mcsweeneys.net/articles/its-decorative-gourd-sea... https://www.mcsweeneys.net/articles/brandon-our-new-lets-go-...

I thought it was a bit strange when my neighbor put up a sign to encourage me. I guess it was all more complicated than I thought.

Re: The New Ten-Factor Authentication Processes

#40
post #36

My grandparents recently got locked out of their Comcast account the other day. They forced multi-factor on all their customers in the last year. You could not imagine how hard it is to have the internet without also having a cell phone. Modern security is a usability nightmare.

Plus, grandparents, the group notorious for their tech-skill. I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

What does HVC mean?
Post reply on HN