Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

131–140 of 392 posts

Re: Passwordless: a different kind of hell?

#131
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

When I use my AMEX card online it sometimes does an extra "validation" step but as I recall I don't have to interact with it. It's probably checking location, etc, and deciding if further validation is necessary.

Have never seen that with VISA or MC.

Re: Passwordless: a different kind of hell?

#132
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

Re: Passwordless: a different kind of hell?

#134
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

> My phone sends all notifications to my desktop

Is this a native phone feature or an app? You're lucky if that's the only place it sends notifications.

Re: Passwordless: a different kind of hell?

#135
post #108

Earlier quoted context omitted.

Why would you submit yourself to using PayPal when you don't have to? Serious question.

Because I don't want to give the credit card details to every site out there. And Because the Resolution Center works wanders with merchants who are not being forthcoming to resolve your problems. I once had an issue that a merchant had delivered less than half of the items that I had ordered, i contacted them and they requested (after 2 days) Proof that I had not received the items. I could only produce the photo of…

Did you do what merchant said? Is it still okay to trust the merchant and lose your only hope with PayPal once you click the resolved button?

Re: Passwordless: a different kind of hell?

#136

Earlier quoted context omitted.

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

In this case, how is eBay responsible for how PayPal and a bank handles things when they hand it off?

Re: Passwordless: a different kind of hell?

#137

Earlier quoted context omitted.

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

> My phone sends all notifications to my desktop Is this a native phone feature or an app? You're lucky if that's the only place it sends notifications.

Why do you say that?

Re: Passwordless: a different kind of hell?

#138

Earlier quoted context omitted.

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

> My phone sends all notifications to my desktop Is this a native phone feature or an app? You're lucky if that's the only place it sends notifications.

He uses KDE Connect. I use is as well. It is amazing, open source, and only sends notifications where you tell it to.

https://kdeconnect.kde.org/

Re: Passwordless: a different kind of hell?

#139
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

With a yubikey everything is stored on the key and the phone is just a terminal, so it travels between phones. Now if you lose the key that's another issue :)

Re: Passwordless: a different kind of hell?

#140
post #125

Earlier quoted context omitted.

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

With a yubikey everything is stored on the key and the phone is just a terminal, so it travels between phones. Now if you lose the key that's another issue :)

Sure, so same problem. Less likely your yubikey will be stolen I guess, but less convenient too (something else to carry)
Post reply on HN