Ask HN: WebAuthn – Replace Password or Second Factor?
31–39 of 39 posts
Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#32Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#332FA is so overused and makes just all workflows taking longer teams/outlook/jira takes 5 minutes to log on and finally starting work. Meanwhile everyone is on slack with no 2FA and on their servers which can/has been breached. Would also be great to not use my private phone for this. Companies already all push their 50 required apps on your private phone...
Yubikeys are so much faster than other 2FA options. Just a quick tap. All of the flavors of "type in this code from your app or that we texted you" are a huge pain by comparison.
Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#34Apple's method of 2FA, where they display the code on one of your Apple devices for secondary confirmation, would be somewhat akin to the scenario of how WebAuthn could work as 2FA by asking for confirmation on supported devices. I find this quite annoying as I don't use an iPhone (a mobile phone is one of the few devices that you always keep with you). That said, the key thing to consider here is security vs ease of…
Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#35WebAuthn should negate the need for a 2nd factor in the traditional sense (you can't steal/extract the WebAuthn private-key). I suppose you could bolt on some kind of WebAuthn after a user/pass login, but I don't see why you wouldn't want it as the first-class citizen replacing the password entirely.
Overall I agree with this, but I think there's a genuine need for a general self-destruct mechanism. Having a key confiscated or taken by force should be preventable in some way, and even if I have a backup key, there needs to be a low-friction way to make a key unusable and unrecoverable. It would also be nice to have a way to quickly de-register a lost key. Having a back-up is great, but it's still a pain to go de-…
Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#36Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#37WAN will usually require a password and second factor to get to the point where you can enroll your device. For example, if you lose your WAN device or need to login a second one, you’ll need credentials (username/password+second factor) to prove who you are to enroll new devices. I opted not to use WAN for now because it feels like a lot of hassle to setup and most users aren’t going to bother enrolling. Who here lo…
Using an acronym no-one else in the thread is using, is not in common usage (this comment is 5:th for a google search for "WAN WebAuthN" and the other results do not use the acronym) and without defining it at the first usage is a bit confusing.
Re: Ask HN: WebAuthn – Replace Password or Second Factor?
#38Earlier quoted context omitted.
Using an acronym no-one else in the thread is using, is not in common usage (this comment is 5:th for a google search for "WAN WebAuthN" and the other results do not use the acronym) and without defining it at the first usage is a bit confusing.
It’s used in Slack/Discord conversations.