Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

1–10 of 392 posts

Re: Passwordless: a different kind of hell?

#3

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

I came to this realisation not too long ago as well. It's saddening to imagine how much better the world in general would be if it weren't for criminals.

Generations before mine talk about their childhood as a wonderful time. Not having to lock their bikes up when going into a shop. Not having security cameras watching their every move. Not having barriers everywhere to prevent theft. My local supermarket introduced receipt scanners a few months ago that block you from exiting. They treat you as a thief by default.

I wish I could live in a high trust society. It sounds like in some parts of world (Japan for example) there are still elements of that.

Re: Passwordless: a different kind of hell?

#4
I think the industry, to some extent, already have reconsidered the session length, see [0] by Auth0 for example (even if it's obv. a PR piece). Nowadays my gut assumption when I use a service with really short sessions is that their security practices are probably questionable.

I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insisted raising it would be to insecure and instead suggested to make MFA optional as it would make the login process smoother…

[0]: https://auth0.com/blog/balance-user-experience-and-security-...

Re: Passwordless: a different kind of hell?

#5

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means.

I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers" as if there are some inherently tainted souls doing bad things just because they are bad.

In my, probably biased, assesment this is especially prevalent in the US public discourse.

Re: Passwordless: a different kind of hell?

#6
Biometrics seem worse-is-better: you now have some unique identifier for me, which is totally swell until the inevitable DB breach.

Which breech will likely be due to an Admin whoopsie of some sort.

Because the people remain the weakest link.

Re: Passwordless: a different kind of hell?

#7
I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past.

First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols.

Then ebay decided they wanted to send me a code by SMS. I'd never enabled that security option, but whatever. I can do that, quick fingerprint to unlock the phone then key in the code.

Then I chose to pay with paypal, requiring a second password. And a 2FA code, this time from a TOTP app. For some reason paypal ask for TOTP every time. Easy enough, quick fingerprint auth then just key in the code.

Then I told paypal I wanted to pay by card, as I always do. They redirected me to my bank, who asked me to use their mobile app to authorise the payment with my fingerprint. After unlocking my phone with my fingerprint, naturally.

Clearly, the days when businesses thought online shopping ought to be low-friction are long gone.

Re: Passwordless: a different kind of hell?

#9
A nice little read! Fun to have a short trip through history, there.

I'm a little disappointed that it didn't talk about passwordless logins, at all, though. I'm thinking of implementing one, and I was hoping this would give me some food for thought! Ah well.

Re: Passwordless: a different kind of hell?

#10
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

In a couple decades I had to verify my bank once with PayPal
Post reply on HN