Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

61–70 of 392 posts

Re: Passwordless: a different kind of hell?

#61
post #19
post #5

Earlier quoted context omitted.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

Nah, thieves are scum. People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for. There are many people out there having a really hard time who would never even think about stealing because they were raised with…

It’s a matter of degree. We often put people in the position where they need to do some pretty terrible, degrading work just to eat. In my view as the alternatives you have get worse, it gets less morally questionable to steal. Furthermore, I think it should largely be evaluated by the harm it does to others, e.g. stealing a car from a sheltered rich person who can afford an uber in an emergency does them much less harm than from a poor person, who may not be able to get to work and put food on the table. Im not even saying it’s fine to steal the rich person’s car, just relatively okay. Thieves are definitely selfish, but so is everyone else in our free market system. We consider it a virtue when the right people do it. Look, most of the time I agree that like, fuck thieves. I just also agree think that the underlying issues are inequality, alienation, and other socioeconomic shit, and that condemning thieves morally is counterproductive because it distracts from the useful changes to prevent them from becoming thieves.

Re: Passwordless: a different kind of hell?

#62
post #17
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

I’m not even embarrassed to say last night I went to check out, saw there wasn’t an Apple Pay option, waited through about 2 minutes of waiting for the credit card details panel to open before bailing.

Re: Passwordless: a different kind of hell?

#63
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, making the process even faster.

Re: Passwordless: a different kind of hell?

#64

Earlier quoted context omitted.

Yeah, assuming that my biometric auth is relatively strong, stays on my device, and is a device-specific hashed representation I have a hard time finding fault. I believe most modern phone's biometrics fit that criteria.

> stays on my device Heh.

OK, so we're at that level of contribution, are we?

Re: Passwordless: a different kind of hell?

#65
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Sounds like you've got some unusual configuration options turned on or something. The most glaring odd thing here is that you apparently don't have your password vault available on the same machine you're shopping from, which seems odd to me. Even so, if I went that route it'd still be easy b/c with the Apple ecosystem, the clipboard is shared between devices. One can copy a password from the phone and paste it on th…

Opening your password manage and displaying the strong password openly on the screen while manually retyping it on a different machine - rather than just installing the password manager on that machine - definitely sounds like a "why are you doing that?" kind of thing.

Likewise I've used a half dozen different cards and multiple bank accounts through PayPal for the last couple decades and can't remember the last time I've had to reauth on any of them during a checkout.

Re: Passwordless: a different kind of hell?

#66
post #8

I understand the frustration with login systems, but why is the title "Passwordless: A Different Kind of Hell" if it doesn't talk about passwordless authentication, like passkeys, magic links, and biometrics?

I was curious about that as well. Since most services implement an email based Forgot Password feature, and 2FA tokens are also often email based, why isn't magic links the default approach now? Seems to be just as secure as password+2FA but easier to use (and probably to implement, as well).

By the title, I thought the article would explore some of the downsides of this approach that I might be missing.

Re: Passwordless: a different kind of hell?

#67
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Sounds like you've got some unusual configuration options turned on or something. The most glaring odd thing here is that you apparently don't have your password vault available on the same machine you're shopping from, which seems odd to me. Even so, if I went that route it'd still be easy b/c with the Apple ecosystem, the clipboard is shared between devices. One can copy a password from the phone and paste it on th…

> Finally, when I pay via Paypal using my Amex, I never have to re-auth to Amex. It just flows through. So it sounds like that's something you've chosen to set up, not something inherent to the process.

To be fair to the parties involved, they might well blame "EU strong customer authentication rules"

Re: Passwordless: a different kind of hell?

#68
I find myself wondering, how much collective time is being lost these days to authentication? I mean, if you have to authenticate using your phone, you have to dig it out of your pocket, sign into the phone, read the text message or use the authenticator app, type in the code...

Re: Passwordless: a different kind of hell?

#69
post #3

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

I came to this realisation not too long ago as well. It's saddening to imagine how much better the world in general would be if it weren't for criminals. Generations before mine talk about their childhood as a wonderful time. Not having to lock their bikes up when going into a shop. Not having security cameras watching their every move. Not having barriers everywhere to prevent theft. My local supermarket introduced…

I agree! And I think we could if we had very harsh punishments. We are way too lenient on crime.

Steal? Life in jail.

Litter? Year long sentence.

Assault? Life in jail.

Criminals are going to commit crime and there is absolutely no evidence that rehabilitation works for those kinds of crime. We need to keep them away from society and change our culture to be entirely intolerant of crime.

Re: Passwordless: a different kind of hell?

#70
post #3

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

I came to this realisation not too long ago as well. It's saddening to imagine how much better the world in general would be if it weren't for criminals. Generations before mine talk about their childhood as a wonderful time. Not having to lock their bikes up when going into a shop. Not having security cameras watching their every move. Not having barriers everywhere to prevent theft. My local supermarket introduced…

Its not really so easy to peg the blame solely on the existence criminals. For one thing what makes a person a criminal changes over time as we redefine what is illegal and what technically illegal acts are given priority enough to enforce.

More importantly though, generations past also often lived in smaller communities then we have today. When your world is smaller and you are only a degree or two of separation away from everyone, people often feel more bound to a certain standard of behavior. Stealing a bike in NYC today is one thing, stealing a bike in a town where you probably know whose bike it is and someone will recognize it if you ever actually ride it is very different.

The larger we grow societal centers and the more we expand the boundaries of our own world, the more we break societal bonds and need laws to enforce rules that are more easily broken when your victim is just another random person living there.

Post reply on HN