Live data from Hacker News

The New Ten-Factor Authentication Processes

mcsweeneys.net

41–50 of 107 posts

Re: The New Ten-Factor Authentication Processes

#41

A sign of the times. Seems like our non-technical brethren find 2FA/MFA a burden? McSweeneys’ satire and parodies are rarely in good jest in my experience. This is a criticism of the move towards 2FA/MFA make no doubt about it. The writer, and the editors who let this through, are not happy about this state of affairs. McSweeney’s isn’t a no-name blog or journal either — its name holds sway over those who work in lit…

Hold the condescension. I wouldn't be surprised if author is from the place where the following definitely literally happened:

At first, there was 2FA where you could either

1. Download the proprietary app OR

2. Get texted the code.

(i.e. no "do-it-yourself" e.g. Google Authenticator option.)

This means you must have a cell phone of nearly any kind. Mostly reasonable.

Turns out; option 2 cost somebody like half a cent every time it was used and also was far more popular than anticipated.

So they just got rid of 2. That's all, no mitigation.

And now you've DRASTICALLY increased the tech requirements for a major public school; I know of IT instructors in the place who did not actually regularly use a phone "fancy" or new enough to handle the official app.

Utter BS.

Re: The New Ten-Factor Authentication Processes

#42
post #40
post #36

Earlier quoted context omitted.

Plus, grandparents, the group notorious for their tech-skill. I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

What does HVC mean?

High value customer, I’d imagine

Re: The New Ten-Factor Authentication Processes

#43
post #40
post #36

Earlier quoted context omitted.

Plus, grandparents, the group notorious for their tech-skill. I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

What does HVC mean?

my guess is "high value customer"

Re: The New Ten-Factor Authentication Processes

#44
post #40
post #36

Earlier quoted context omitted.

Plus, grandparents, the group notorious for their tech-skill. I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

What does HVC mean?

[deleted]

Re: The New Ten-Factor Authentication Processes

#45
post #9

Earlier quoted context omitted.

» I don't think there's quite as much malice as you seem to read into it. Requiring signing into my Microsoft account (with two step authentication code) every twenty four hours on a company laptop you control is obnoxious. You should educate and empower your employees, not treat them as the weak link in your armor.

It’s naive to not treat them like the weak link though, because they really are. No amount of education (that is routinely ignored) is enough to actually change that.

Routinely ignored implies that it's a deliberate action on the part of an employee. I don't think that's the case. The yearly security training gets treated just like the airplane safety briefing. Folks pay attention the first couple of times they encounter it, but when they realize they'll never be in a situation then it gets classified as 'could be useful, but will probably never need.'

The yearly security training is probably just a compliance checkbox companies do. If they wanted an educated workforce that practices security first there are other far more effective approaches.

Of course, that all ignores the fact that employees are weak links not because they are dumb, but because they don't have an incentive to protect the company when they or their families are put in danger by a threat actor.

Re: The New Ten-Factor Authentication Processes

#46
post #40
post #36

Earlier quoted context omitted.

Plus, grandparents, the group notorious for their tech-skill. I've just taken over all my elder family accounts for internet, TV, phone, etc. Much easier. And all the vendors treat me as HVC cause I'm paying for multiple services on their platforms.

What does HVC mean?

"High value customer", if I had to guess.

Re: The New Ten-Factor Authentication Processes

#47
post #32

the problem with mcsweeneys is that it's a humor publication that fails at humor. it's like those sitcoms from the 80s where they had to add laugh tracks because no one actually laughed while watching them. at best it's something for young adults to forward around to try and look sophisticated, but like those young adults, it misses the point entirely by trying much too hard.

There aren't very many things that someone can say that are universally wrong, but "I don't think this is funny and therefore it is failed humor" is probably pretty close

Re: The New Ten-Factor Authentication Processes

#48

A sign of the times. Seems like our non-technical brethren find 2FA/MFA a burden? McSweeneys’ satire and parodies are rarely in good jest in my experience. This is a criticism of the move towards 2FA/MFA make no doubt about it. The writer, and the editors who let this through, are not happy about this state of affairs. McSweeney’s isn’t a no-name blog or journal either — its name holds sway over those who work in lit…

I found it to be less a satire of 2FA/MFA than of college administration busybodies in general.

Re: The New Ten-Factor Authentication Processes

#49
post #14

Here's a question spurred by the post. Who administers and issues VINs? I assume VINs are the same throughout the world. Is there some sort of worldwide regulatory body, or is compliance by manufacturers simply a gentlemens' agreement?

I think the UK uses AWS QLDB to issue vehicle ownership. I don’t know if VIN’s are recognized globally, but I really appreciate that non-repudiation use of the blockchain.

Re: The New Ten-Factor Authentication Processes

#50
Worst I've seen by far for getting into a desktop banking website recently, it felt like a parody:

1. On desktop: Enter username and answer to a random memorable question like "your first pet" (password manager will probably fail to autofill this). You're then prompted for a "mobile security code".

2. On mobile app: Enter username + different password. Need to scroll, tap 7 items and then enter a password to get a mobile code you then have to type into the desktop app.

Getting the mobile security code logs you out of the mobile app and logging into the mobile app will log you out of the desktop app.

It's like they didn't do any user testing and think that more steps = better security.

Lots of UK banks also ask for random parts of your password only e.g. "enter the 2nd, 10th and 5th character from your password" which is super tedious to do correctly because you can't use muscle memory or autofill. This is to defeat key loggers? Isn't that what 2FA would do? You'd think banks would be clued up on this.

Post reply on HN