Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

111–120 of 392 posts

Re: Passwordless: a different kind of hell?

#112
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel. My credit card card [1] has fundamentally changed my online purchasing experience as it bri…

I've been using Privacy.com for this "create single use credit card" for years now. They make money via the interchange fees, afaik, and not by selling your data stream.

Re: Passwordless: a different kind of hell?

#113
SMS-based 2FA is still vulnerable to phishing, but U2F is not. This has been solved for a while now, but I guess it's still a hassle for most folks to use them.

I got my whole family Yubikeys a while back, and it seems to be going pretty well.

Re: Passwordless: a different kind of hell?

#114
post #95

Earlier quoted context omitted.

I've never had to authenticate with a bank for using a card? Is this common for you?

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

The regulation for this is PSD2.

https://en.wikipedia.org/wiki/Payment_Services_Directive

Re: Passwordless: a different kind of hell?

#115
Something that often gets overlooked in these discussions is the impact of all this on older people and people with intellectual disabilities. Managing all of this is annoying to an average person, but can literally be impossible for an older person with a memory disorder. It creates a lot of additional vulnerability for them, because they now need to trust someone to help them manage their accounts. It also puts a heavier burden on people in customer service who have to deal with often irate older customers who are having trouble managing their accounts.

Re: Passwordless: a different kind of hell?

#116
post #17
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

[deleted]

Re: Passwordless: a different kind of hell?

#117
post #5

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

In a society that considers most rich people "bad actors" or "evildoers" (i.e. they'd never be that rich if this was a fair game), that's pretty erm… rich of you to say.

Re: Passwordless: a different kind of hell?

#118
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I pretty much never have to do a 2FA with Paypal. And it never redirects me to the bank (credit card).

I also don't do this on my phone, but on a regular PC.

Re: Passwordless: a different kind of hell?

#119
post #113

SMS-based 2FA is still vulnerable to phishing, but U2F is not. This has been solved for a while now, but I guess it's still a hassle for most folks to use them. I got my whole family Yubikeys a while back, and it seems to be going pretty well.

How do you backup access? The one thing that's stopped me from pulling the trigger on U2F is if that device is lost, stolen, or broken then I'm hosed, right?

With standard 2FA, I have backup devices and codes that I can start restart from scratch if my phone is ever lost/stolen/broken.

Re: Passwordless: a different kind of hell?

#120
post #17

Earlier quoted context omitted.

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across.

Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)

Post reply on HN