Live data from Hacker News

The New Ten-Factor Authentication Processes

mcsweeneys.net

51–60 of 107 posts

Re: The New Ten-Factor Authentication Processes

#51
post #31

how do you type sign language

There are many systems, here's an overview: https://aslfont.github.io/Symbol-Font-For-ASL/ways-to-write....

E.g. for one of the systems in the article:

> It is written left to right, and uses subscripts, superscripts and diacritics. Each sign is written in this order: handshape, orientation, location, actions.

Re: The New Ten-Factor Authentication Processes

#52
post #14

Here's a question spurred by the post. Who administers and issues VINs? I assume VINs are the same throughout the world. Is there some sort of worldwide regulatory body, or is compliance by manufacturers simply a gentlemens' agreement?

I believe they're administered by Vin Diesel.

Re: The New Ten-Factor Authentication Processes

#53

Worst I've seen by far for getting into a desktop banking website recently, it felt like a parody: 1. On desktop: Enter username and answer to a random memorable question like "your first pet" (password manager will probably fail to autofill this). You're then prompted for a "mobile security code". 2. On mobile app: Enter username + different password. Need to scroll, tap 7 items and then enter a password to get a mo…

Is this known as the Rube Goldberg Machine authentication process?

Re: The New Ten-Factor Authentication Processes

#54

Sigh. We're working to normalize better UX around account security at https://clerk.dev It's a sordid affair, but we're making progress. We've reduced our average time to sign-in by about 20% since our launch 6 months ago. (There's nothing to say our starting point was very good, but we do think about this very consciously.) If you're working to improve your sign-in flow, our biggest wins so far have been: - OAuth bu…

> We've reduced our overall sign-in speed by about 20%

So it's slower now, or did you mean to say you've reduced the time to sign-in?

Re: The New Ten-Factor Authentication Processes

#55

Earlier quoted context omitted.

I personally use 1password for authenticator codes - highly recommend if you haven't seen it: https://support.1password.com/one-time-passwords/ Edit: Didn't answer the actual question - it's something we can look into. My instinct is that offering this wouldn't drastically change the security model, as long as we can be confident your password actually came from a secure password manager. Since some password managers…

But doesn't this completely defeat the purpose of the codes, since they're no longer a second factor? I'd rather just not have the codes, as they're still a significant annoyance with next to zero benefit.

There are still some benefits. Your password can probably be bypassed with a "forgot password" flow while the TOTP code cannot.

Aside from that, though, I think it's reasonable to argue that the security of password+code in 1password is equivalent to just password in 1password.

Re: The New Ten-Factor Authentication Processes

#56

Worst I've seen by far for getting into a desktop banking website recently, it felt like a parody: 1. On desktop: Enter username and answer to a random memorable question like "your first pet" (password manager will probably fail to autofill this). You're then prompted for a "mobile security code". 2. On mobile app: Enter username + different password. Need to scroll, tap 7 items and then enter a password to get a mo…

One time I signed up on a site with 'Sign in with Google'. Months later, I wanted to delete my account, but the deletion process required I enter my account's password, which obviously I was never prompted to set up. The site wouldn't let me do a 'Forgot password' to set a password, so the account was impossible to delete.

Re: The New Ten-Factor Authentication Processes

#57

Sigh. We're working to normalize better UX around account security at https://clerk.dev It's a sordid affair, but we're making progress. We've reduced our average time to sign-in by about 20% since our launch 6 months ago. (There's nothing to say our starting point was very good, but we do think about this very consciously.) If you're working to improve your sign-in flow, our biggest wins so far have been: - OAuth bu…

> We've reduced our overall sign-in speed by about 20% So it's slower now, or did you mean to say you've reduced the time to sign-in?

Fixed :) Thank you

Re: The New Ten-Factor Authentication Processes

#58

Worst I've seen by far for getting into a desktop banking website recently, it felt like a parody: 1. On desktop: Enter username and answer to a random memorable question like "your first pet" (password manager will probably fail to autofill this). You're then prompted for a "mobile security code". 2. On mobile app: Enter username + different password. Need to scroll, tap 7 items and then enter a password to get a mo…

I'd change banks!

Re: The New Ten-Factor Authentication Processes

#59
My favourite stupidity is related to self-service password reset questions.

You know the type: "What's your favourite animal?", and other easily-guessed and easily obtained information hackers can use.

I always put in some gibberish by mashing the keyboard and make sure to record them somewhere safe just in case I need a password reset. I memorise my password and that should be fine, right?

Well, I was overseas with just my phone available to me, and one of the banking apps refused to let me use my valid password without also entering my password reset answers!

They misused the value I was only expecting to need for a reset for access.

I was totally locked out of my bank account with no recourse until I got back home and could look up the gibberish string used for the answers.

Re: The New Ten-Factor Authentication Processes

#60

my bank insisted that i add a phone number to my account when i called them today. i declined and when pressed briefly explained sim swapping and declined again. a glaring and obvious flaw in the integrity of using a phone number for id verification was not even in the lexicon of this establishment that safeguards nothing less than all of my literal fucking money. they then went on to find that i actually did have a…

Unfortunately people like you (and me), who actually have strong passwords, let alone who understand in any detail what constitutes a strong password, are a tiny minority. They have to design for the lowest common denominator.

And even those of us with strong passwords, and a strong understanding of cyber security, are vulnerable to phishing and other attacks, that can be defended against by using MFA.

Obviously MFA can be taken to ridiculous "ten factor" extremes. But sticking with, or going back to, just passwords, isn't the solution.

Post reply on HN