Live data from Hacker News

Passwords Are Fine

herman.bearblog.dev

61–70 of 169 posts

Re: Passwords Are Fine

#61
post #59

> 2. People don't have their phone on them all the time (and some don't even have a smartphone). I live in rural Western Australia with almost zero phone coverage, and this is a huge problem. I'm terrified of all these services wanting my phone number, or bugging me to turn on phone 2FA, because the moment that happens, I lose access to that service . ChatGPT that everyone is spamming on every discussion? I can't eve…

If you don’t have a smartphone, or your phone cannot connect to a service, why is authentication a problem? If you don’t network access you lose access to the network, this isn’t exactly a surprise.

I assume he is talking about SMS. Maybe a virtual SMS inbox is the solution.

Re: Passwords Are Fine

#62
What I find increasingly annoying is third parties (i.e. those whose primary service isn't to provide authentication or MFA, specifically) trying to route me through their mobile apps for a second factor.

For example, GitHub and Google (via their Gmail mobile app) are constantly nagging me to open their apps for certain actions such as modifying security settings on a GitHub repository or even just logging in to Google Workspace.

While certainly more secure than SMS, I'd like to use an authenticator app of my own choosing for that process (e.g., 1Password or Authy). While that's still possible, UX-wise that requires an additional step and possibly also brings about the risk of being flagged by some internal fraud detection system.

To me, this feels like they're trying to promote their apps and increase user retention and interaction by means of what superficially looks like a beneficial security feature.

Re: Passwords Are Fine

#63
post #10

Earlier quoted context omitted.

Of course you despise it. Security always comes at the cost of convenience.

Those who would give up essential Security, to purchase a little temporary Convenience, deserve neither Security nor Convenience. — Frankmin Benjalin

Security with the cost of convenience comes with the cost of security.

Re: Passwords Are Fine

#64

> 2. People don't have their phone on them all the time (and some don't even have a smartphone). I live in rural Western Australia with almost zero phone coverage, and this is a huge problem. I'm terrified of all these services wanting my phone number, or bugging me to turn on phone 2FA, because the moment that happens, I lose access to that service . ChatGPT that everyone is spamming on every discussion? I can't eve…

I have a dumbphone. Until recently I could not care less about losing it. But I realised that since it's not PIN protected (I could but don't want to do it), losing is a security issue. People can find my phone, match my phone number to my email address using leaked data, try these credentials on different services and wait until they get a reset password SMS.

So by forcing me to add my phone number some services actually decrease the security of my account.

Re: Passwords Are Fine

#65
post #51

For a layperson, the passwords are easy to understand and provide enough ways to shoot themselves in the foot. Unless you are an expert, password hygiene can rarely be accomplished. For a layperson, passkeys are difficult to understand, but provide out-of-the-box hygiene and security. Passwords are not fine. What we need is better explanation/education of passkeys.

> Unless you are an expert, password hygiene can rarely be accomplished.

Why? Aren’t built-in password managers such as iCloud Keychain (which also auto-generates secure passwords) enough?

Re: Passwords Are Fine

#66

> 2. People don't have their phone on them all the time (and some don't even have a smartphone). I live in rural Western Australia with almost zero phone coverage, and this is a huge problem. I'm terrified of all these services wanting my phone number, or bugging me to turn on phone 2FA, because the moment that happens, I lose access to that service . ChatGPT that everyone is spamming on every discussion? I can't eve…

>I live in rural Western Australia with almost zero phone coverage, and this is a huge problem. I'm terrified of all these services wanting my phone number, or bugging me to turn on phone 2FA, because the moment that happens, I lose access to that service.

Have you tried enabling Wi-Fi calling or switching to a carrier that supports it? At least for my carrier and iOS, you can send/receive SMS messages (yes, the green bubbles) through Wi-Fi.

Re: Passwords Are Fine

#67
post #35

Earlier quoted context omitted.

> it seems like a dangerous crutch than a useful technology Not to sidetrack, but could you expound further? I struggle to reach the blanket conclusion of “not useful”. I don’t really see how it’s a crutch, more than any other assistance tool like Google, StackOverflow, code-completion or actual docs. Hallucination is a separate problem, which is solved by using fine-tuned models.

> Hallucination is a separate problem, which is solved by using fine-tuned models. They won't solve the main cause of hallucination: prompt has zero connection to generated text other than probability. ChatGPT do not generate answers, it comes up with something that looks like an answer. There is a good chance it is the answer, but you can't guarantee it. I believe this particular problem won't be solved, unless rese…

Yes, but pattern matching and probability will solve for the vast majority of usecases. Heck, it already works quite well and offers value.

I don’t need 100% truth, because reading multiple docs myself and piecing things together has tons of potential pitfalls too.

Re: Passwords Are Fine

#68
post #2

Of course passwords are fine. What's not fine is getting billions of people to change their behavior and switch to and use a password manager (that's not chrome). You could even argue passwords are better than passkeys for those with strong password hygiene. However when it to the masses, the convenience-security tradeoff of something like passkeys is always going to be better. And for the nerds and geeks, passwords…

Why not chrome?

Not the parent but the problem is that Chrome (sub. Firefox and Safari, these are problems with pretty much all browsers) isn't a password manager, its a password autofiller.

The result is that what should be crucial things like "how do we ensure permanency of the passwords file" are treated as very second rank - profile corruption usually is met with "remove the entire profile", which also ditches the password database. Literally every other password manager has some sort of tool available that makes it very clear where your data is stored and emergency backup options.

Chrome also doesn't like it if the login form doesn't look like most other login forms (and because this is the internet, you're gonna at some point run into weird login forms). It also can behave really funny if the site combines the user registration form with the user login form (which a lot of webshops do) by putting the autofill information in the registration form instead of the login form.

Add to that a very subpar experience in manually filling the right fields and "why not Chrome" should have a very clear answer.

Re: Passwords Are Fine

#69

> 2. People don't have their phone on them all the time (and some don't even have a smartphone). I live in rural Western Australia with almost zero phone coverage, and this is a huge problem. I'm terrified of all these services wanting my phone number, or bugging me to turn on phone 2FA, because the moment that happens, I lose access to that service . ChatGPT that everyone is spamming on every discussion? I can't eve…

I have a dumbphone. Until recently I could not care less about losing it. But I realised that since it's not PIN protected (I could but don't want to do it), losing is a security issue. People can find my phone, match my phone number to my email address using leaked data, try these credentials on different services and wait until they get a reset password SMS. So by forcing me to add my phone number some services act…

You’re absolutely right on that last part.

Making phone numbers required for signing up was only nominally to improve security. Overall, it’s a net negative for privacy and security, and only benefits the service provider by allowing them to track you (they can buy data on that phone number and create a profile on you) + reducing the number of people calling/emailing them because the user is locked out of their account.

Re: Passwords Are Fine

#70

What I find more annoying is the aggressive insistence of bigcorps to do everything possible with 2FA except actually just use the damn 2FA code I already have set up in my password manager. SMS, emails, pushing codes to random devices I'm logged in on, whatever.

I recently got a pair of yubikeys… they have been around about ten years already and support industry standards. Guess how many services I use support them? A smaller fraction than I’d like.

My employer had a program where you could put in a request and get a free yubikey. Turns out they basically only work with Chrome (no Firefox, no terminal-based auth), so none of my team actually ever uses theirs because it's not really more convenient.
Post reply on HN