Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

31–40 of 392 posts

Re: Passwordless: a different kind of hell?

#31
post #14

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

Just turn on Passkeys on GitHub, then you don't need 2FA/TOTP. It's also faster.

My password manager autofilling will always be faster than any other option, especially one that requires me to pull out my phone, navigate to my authenticator app, switch to your app (which will only become more time-consuming as more sites require it), then type in the code by hand.

The only thing that can compete with password managers on user experience is just actually remembering they're logged in instead of pointlessly logging them out every single day for no reason.

Re: Passwordless: a different kind of hell?

#32

I have 743 login credentials (1984-present). Trusting 743 “randos on the internet” to safeguard “my” data, and give me access to use it. Insanity. Agent-Centric systems where I retain signing keys to authorize access to (and transactions using my) data are the way forward. A Key Fob (like you have for your car) is not onerous, and methods for recovery using trusted community members is practical. Holochain (and the H…

I mean, either those services need your data or they don't. I don't see how requiring you to upload or decrypt your data every time you want to use a service would be feasible for most things.

Re: Passwordless: a different kind of hell?

#33
post #17
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Re: Passwordless: a different kind of hell?

#34
post #19

Earlier quoted context omitted.

Nah, thieves are scum. People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for. There are many people out there having a really hard time who would never even think about stealing because they were raised with…

This is why we can't have nice things.

I don't know how I'm supposed to have any sympathy for thieves when myself and my family have been victims of multiple thefts totalling tens of thousands of pounds over the past years. I comforted my mum while she bawled her eyes out for hours when her car was stolen off of our driveway at the crack of dawn. Fuck thieves.

Re: Passwordless: a different kind of hell?

#35
post #8

I understand the frustration with login systems, but why is the title "Passwordless: A Different Kind of Hell" if it doesn't talk about passwordless authentication, like passkeys, magic links, and biometrics?

It talks about passkeys and biometrics though.

At the very end, as possible alternatives to the hell they're describing.

Re: Passwordless: a different kind of hell?

#36

Earlier quoted context omitted.

Why would you submit yourself to using PayPal when you don't have to? Serious question.

It's quicker than entering your credit card details and address again and again.

If you use a password manager (which they say they do) it's much quicker to just save that info and automatically populate it. Doubly so considering the MFA hell they went through.

Re: Passwordless: a different kind of hell?

#37

Earlier quoted context omitted.

Why would you submit yourself to using PayPal when you don't have to? Serious question.

It's quicker than entering your credit card details and address again and again.

it's also convenient for managing subscriptions

Re: Passwordless: a different kind of hell?

#38

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

This happens because people won’t use a password manager and insist that “monkey123” is their super-secret unguessable password. The solution is to force them to use some kind of credential store (SMS 2FA, passkeys), because they can’t be entrusted to just hit the “generate secure password & save” prompt in the browser.

Re: Passwordless: a different kind of hell?

#39
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Why would you submit yourself to using PayPal when you don't have to? Serious question.

Up until not so long ago that was the easiest "payment wallet" to have around.

Want to have charges go direct to your bank for 2 weeks ? you move it up on the list.

Want to try a new card but are not sure you'll keep using it ? add to the wallet and move up or down depending on how much you want to use it.

And it also managed subscriptions.

It is now a steaming pile of garbage for so many reasons, and it has always been a death trap for any small merchant, but they gave a fairly good shot at the wallet side of things. Good luck getting Nintendo for instance trust any other third party wallet system.

Re: Passwordless: a different kind of hell?

#40
> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it.

Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording of the story indicates a slightly different issue:

> for he could not frame to pronounce it right.

It's not a spelling difference per se, it's (AIUI) that the Gileadite pronunciation uses a phoneme that was not used at all in the Ephraimites spoken language, so an Ephraimites soldier was literally incapable of pronouncing the word "correctly".

e.g. How some spoken dialects/accents do not use a rhotic "r", or do not distinguish between "l"/"r", or are not tonal languages. If you have not already learned how to make that specific sound, and distinguish it from the other one, through repeated practice, you will be unable to replicate it properly. And this will be the case no matter how the word is spelled, or even if you try to immediately copy someone saying it the exact way they want you to say it.

[0] https://en.wikipedia.org/wiki/Shibboleth

Post reply on HN