Live data from Hacker News

Passwords Are Fine

herman.bearblog.dev

151–160 of 169 posts

Re: Passwords Are Fine

#151
They missed the point that users with passwords are often extremely prone to phishing; especially with certain popular MiTM frameworks. We have the technology available to combat that, so, please yes, let’s move away from open sesame authentication.

Re: Passwords Are Fine

#152

Earlier quoted context omitted.

I'm in a similar boat. Not so much service, but I move around internationally and change sims a lot. I dont even have a sim most of the time, I'm on wifi 99% of the time. Don't want to pay outrageous fees for Google FI or the like, as literally all I need it for is to get into online banking (who have decided sms 2fa is now compulsory, without offering any other options like an authenticator app). I'm currently locke…

> outrageous fees for Google FI Last I checked, they were asking for $20 / month for unlimited calling and texting. Do you consider that outrageous? As an alternative, Google Voice will host your phone number for free. It works with every WiFi connection and even while traveling internationally. Have you considered that?

That's interesting, will have to check that out. People have mentioned online sms, which sounds pretty much like what I need.

But yeah re:Google Fi, $240/y to recieve maybe 3 sms is pretty bad imo. And unlimited is only within US.

Re: Passwords Are Fine

#153
Strange article I must admit. They describe common pitfalls as: 1. People don't have their phone on them all the time (some don't have a smartphone) 2. New users don't understand these methods of authentication 3. General much more complicated than a basic email/password combo

However, recommendations were to use Apple's authentication methods that are not device manufacturer agnostic, download and use a password manager (complicated) or use 2FA apps.

All of these require a smartphone and are additional methods of authentication.

Overall, you need MFA and try not to use SMS MFA.

Re: Passwords Are Fine

#154
post #7

I'm glad they said it. As a user I just despise MFA. I hate having to keep my phone with me while I work. I hate the disruption in flow logging into everyday services like AWS. Passwords are so much better.

You despise MFA until it saves your arse

Re: Passwords Are Fine

#155
post #7

I'm glad they said it. As a user I just despise MFA. I hate having to keep my phone with me while I work. I hate the disruption in flow logging into everyday services like AWS. Passwords are so much better.

You despise MFA until it saves your arse

Well, you probably never actually find out when that is.

Re: Passwords Are Fine

#156
post #70

Earlier quoted context omitted.

I recently got a pair of yubikeys… they have been around about ten years already and support industry standards. Guess how many services I use support them? A smaller fraction than I’d like.

My employer had a program where you could put in a request and get a free yubikey. Turns out they basically only work with Chrome (no Firefox, no terminal-based auth), so none of my team actually ever uses theirs because it's not really more convenient.

That's not true I use mine only with Firefox. And done small companies like Google, Apple, PayPal fully supports Yubikey.

Re: Passwords Are Fine

#157

Earlier quoted context omitted.

I'm in a similar boat. Not so much service, but I move around internationally and change sims a lot. I dont even have a sim most of the time, I'm on wifi 99% of the time. Don't want to pay outrageous fees for Google FI or the like, as literally all I need it for is to get into online banking (who have decided sms 2fa is now compulsory, without offering any other options like an authenticator app). I'm currently locke…

> outrageous fees for Google FI Last I checked, they were asking for $20 / month for unlimited calling and texting. Do you consider that outrageous? As an alternative, Google Voice will host your phone number for free. It works with every WiFi connection and even while traveling internationally. Have you considered that?

If you use Google Voice, don't get too attached to the number. They'll reclaim it in a heartbeat for various reasons.

Re: Passwords Are Fine

#159
post #80
post #59

Earlier quoted context omitted.

If you don’t have a smartphone, or your phone cannot connect to a service, why is authentication a problem? If you don’t network access you lose access to the network, this isn’t exactly a surprise.

> If you don’t have a smartphone, or your phone cannot connect to a service, why is authentication a problem? If you don’t network access you lose access to the network It might seem surprising these days, but the parent poster might have network access through means other than a phone.

Then use that other device for the auth flow? I'm not surprised by that, but am surprised by your implication that it would still involve your phone.

Re: Passwords Are Fine

#160
post #4

“Passwords are fine” only in a theoretical world where everyone uses passwords “correctly” and securely. But in the real world people don’t, so passkeys are a much better and easier method. I fail to understand how educating billions (?) of people about proper password hygiene is faster or simpler than moving all authentication to a “tap this button to magically log in” method.

> passkeys are a much better and easier method Disagree. This isn't possible with passkeys: - logging into a service with email and brain-stored password from any device With passkeys, your phone becomes your password, so don't break it, lose it, let it die, forget it in the car, become too old, let your kids use it, etc > “tap this button to magically log in” method That only works if the device you tap it on is the…

you either can remember all your passwords and then you are fucked or you use a pass manager

passkeys will be stored in a pass manager and they can be recovered with device pin and master pass, I think they will be exportable too

so yes, you can log in with brain stored stuff

I guess you need a device to log in? then you log in to your pass manager and you can log in to anywhere

only this way you have to remember a passcode and a master pass, not 1000 passwords and you need your master pass 5x/10 years and your passcode every other day and you log in with your device and your biometrics

passkeys have issues but what you are saying is pure shit

Post reply on HN