Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

91–100 of 392 posts

Re: Passwordless: a different kind of hell?

#91
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Ever since I started using brave browser I have to do all of this shit. On firefox i dont. Chrome, i definitely don't.

Re: Passwordless: a different kind of hell?

#92
post #72

Earlier quoted context omitted.

Please explain what is the root problem and how solve it.

Healthcare should be universal and require almost no paperwork from the patient. Our current system is too bloated and either requires a job with good insurance or weeks/months of research into your options. Agencies like the DEA should be abolished and possession/use of drugs should not equal prison time or anything on your record. Of course, things like driving impaired are still punished because you're endangering…

Sweden has universal healthcare and education is free, but still Sweden suffers from massive crime wave.

Sweden's welfare state is a left wing dream come true, however the bad news for the left is that it empirically disproves every left wing idea about crime and society.

Re: Passwordless: a different kind of hell?

#93
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

Pretty common in Europe these days, due to PSD2 regulation.

Re: Passwordless: a different kind of hell?

#94
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

MFA is required in the EU:

https://en.wikipedia.org/wiki/Strong_customer_authentication

Re: Passwordless: a different kind of hell?

#95
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory.

And a credit card I've got recently also asks for a second code, after the 3ds code.

Re: Passwordless: a different kind of hell?

#96
post #95

Earlier quoted context omitted.

I've never had to authenticate with a bank for using a card? Is this common for you?

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

By the way, the last time I checked using 3ds means that it's "impossible that the transaction was fraudulent" and thus you can't cancel it

Re: Passwordless: a different kind of hell?

#97

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes.

So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow).

When I bought a new iPhone, apparently none of my stored information got copied over. The apps did, but none of the information for those apps (for example, the TOTP info maintained by the authenticator I used). So, I went to log in to Github, opened up my authenticator app, and it was blank.

Thankfully I had the codes...back at home, in a drawer, guarded by a cat, so I wasn't completely doomed, but it ruined the day to be sure until I could get home and recover it and recalibrate my TOTP app.

Oh, guess who has a photo of their recovery codes on their phone now?

Re: Passwordless: a different kind of hell?

#98
My biggest pet-peeve is when they just ask for your email address, then on the next page inform you they've emailed you a one-time login code, and then you need to hunt for the link in small text along the lines of "Log in with a password instead".

Re: Passwordless: a different kind of hell?

#99

Earlier quoted context omitted.

I've never had to authenticate with a bank for using a card? Is this common for you?

MFA is required in the EU: https://en.wikipedia.org/wiki/Strong_customer_authentication

Really interesting, here in Mexico I think that's unheard of, what I have to use is a digital card with a dynamic 3 digit cvv that's generated on my app.

Re: Passwordless: a different kind of hell?

#100
post #95

Earlier quoted context omitted.

I've never had to authenticate with a bank for using a card? Is this common for you?

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

> it's always compulsory

No, it's the shop that decides actually. More and more accepts do direct payments from card numbers without additional checks, by the way.

Post reply on HN