Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

101–110 of 392 posts

Re: Passwordless: a different kind of hell?

#101

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

I think it's the people who pick bad passwords that are making login flows worse. Bad actors are the reason we have passwords in the first place, yes, but authentication still shouldn't be as bad an experience as it is today. As it turns out, after thirty years of internet access, people just suck at picking a good password.

When I generate random passwords, people complain that they're unreadable. When I ask them why the password they need to enter once every two years would need to be readable, they just shrug. When I bring up the ability to save passwords to their devices using a password manager or their browser, they say they're "not into IT" and ignore any advice beyond that. Then they change their passwords to Welcome2024!, and that's why we have to make things more complicated. I don't care about most random accounts, but the Welcom2024! people are the ones safeguarding personal data, medical information, and so much more, and if they don't care, you have to force them to use computers responsibly.

Most websites would be perfectly fine with just a username and a randomly generated password. Even eBay or banks, if we're talking about However, in real life, we can't do that, because when the Welcome2024! people get their accounts taken over, their digital wallets drained, their credit cards emptied out, and their life ruined by people on another continent, it's always the websites' fault. People love to say "Google/eBay/PayPal/my bank should've prevented this" but when these services take steps to prevent that stuff, they get mad that everything gets so complicated.

Bad actors will always cause things to be worse, but the general apathy the general public has to digital safety is the reason why it's _this_ bad.

Re: Passwordless: a different kind of hell?

#102

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

A modern example that might be intuitive to native English speakers is asking people to pronounce "The rural squirrel measures the tomb". You will be able to tell most Germans apart from native speakers by the first word alone

Re: Passwordless: a different kind of hell?

#103
post #96
post #95

Earlier quoted context omitted.

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

By the way, the last time I checked using 3ds means that it's "impossible that the transaction was fraudulent" and thus you can't cancel it

Yep, that's why it caught on by shop despite being a friction.

Re: Passwordless: a different kind of hell?

#104
post #17

Earlier quoted context omitted.

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

The idiots removed the 1-click checkout feature and replaced it with a Dropbox to choose which address to deliver to, but it no longer ties that address to a payment method.

Re: Passwordless: a different kind of hell?

#105
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel.

My credit card card [1] has fundamentally changed my online purchasing experience as it bridges what I feel is a gap between new payment methods (Apple, Google, et al) and classic payment methods (CC).

An ounce of prevention is worth a pound of cure.

When I purchase something line, I create a new one-time card (three taps on my phone) and use that new, valid CC for purchasing. Everybody takes a CC. The card is instantly deleted after purchase, and I don't have to worry about my paypal account, apple pay account, google wallet account, ghost subs, account hacks, identity theft -- the works.

[1] https://x1creditcard.com/

Re: Passwordless: a different kind of hell?

#106
Weird post. It's a good history of authentication, including offline and online, and I like the ratings.

But the title seems like pure click bait, as the author didn't spend more than 2 sentences on passkeys/Webauthn (which is the typical tech for passwordless solutions nowadays).

I have my own issues with Webauthn usability and was expecting a deeper dive into that.

That larger problem, of course, is that security and ease of use are in tension. Always were, always will be.

Re: Passwordless: a different kind of hell?

#107
post #65

Earlier quoted context omitted.

Sounds like you've got some unusual configuration options turned on or something. The most glaring odd thing here is that you apparently don't have your password vault available on the same machine you're shopping from, which seems odd to me. Even so, if I went that route it'd still be easy b/c with the Apple ecosystem, the clipboard is shared between devices. One can copy a password from the phone and paste it on th…

Opening your password manage and displaying the strong password openly on the screen while manually retyping it on a different machine - rather than just installing the password manager on that machine - definitely sounds like a "why are you doing that?" kind of thing. Likewise I've used a half dozen different cards and multiple bank accounts through PayPal for the last couple decades and can't remember the last time…

> Opening your password manage and displaying the strong password openly on the screen while manually retyping it on a different machine - rather than just installing the password manager on that machine - definitely sounds like a "why are you doing that?" kind of thing.

If the machine with the passwords is less exposed it's on average a lot safer (but now you have the problem of keyloggers of course)

Re: Passwordless: a different kind of hell?

#108
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Why would you submit yourself to using PayPal when you don't have to? Serious question.

Because I don't want to give the credit card details to every site out there. And Because the Resolution Center works wanders with merchants who are not being forthcoming to resolve your problems. I once had an issue that a merchant had delivered less than half of the items that I had ordered, i contacted them and they requested (after 2 days) Proof that I had not received the items. I could only produce the photo of the opened package which was clearly too small to contain everything they were supposed to deliver and the weight in the package label that clearly was too little for everything I was supposed to get. They tried to stall asking proof that i had not received a second package with the rest of the missing items.(How can you prove a negative?

I got fed up and opened a refund ticket with paypal describing the problems and within 30 min the merchant contacted me promising to send the missing items and refund 20% of the cost if i closed the ticket in paypal.

Re: Passwordless: a different kind of hell?

#109
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel. My credit card card [1] has fundamentally changed my online purchasing experience as it bri…

>Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC.

Paypal absolutely lets you stop recurring payments unilaterally on their side. I use Paypal for subscriptions wherever it's offered precisely for this reason.

https://www.paypal.com/us/cshelp/article/what-is-an-automati...

Re: Passwordless: a different kind of hell?

#110

Earlier quoted context omitted.

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel. My credit card card [1] has fundamentally changed my online purchasing experience as it bri…

>Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Paypal absolutely lets you stop recurring payments unilaterally on their side. I use Paypal for subscriptions wherever it's offered precisely for this reason. https://www.paypal.com/us/cshelp/article/what-is-an-automati...

That's news to me! Thank you for sharing!
Post reply on HN