Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

141–150 of 392 posts

Re: Passwordless: a different kind of hell?

#141
post #108

Earlier quoted context omitted.

Because I don't want to give the credit card details to every site out there. And Because the Resolution Center works wanders with merchants who are not being forthcoming to resolve your problems. I once had an issue that a merchant had delivered less than half of the items that I had ordered, i contacted them and they requested (after 2 days) Proof that I had not received the items. I could only produce the photo of…

Did you do what merchant said? Is it still okay to trust the merchant and lose your only hope with PayPal once you click the resolved button?

No I asked the merchant to commit to resend the missing items inside the resolution center and resolved the issue only after the items arrived.

The aim is not "profit" but to get the deserved attention and bypass clear stalling tactics like having to prove a negative. Needles to say that I Did not ever use that merchant again.

Re: Passwordless: a different kind of hell?

#142

Earlier quoted context omitted.

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

In general I agree, but KDE Connect is not random software and it's fucking awesome, especially if you are a KDE user, for a lot of reasons. The use-case described in the grandparent is just one of many handy things available via KDE Connect

Re: Passwordless: a different kind of hell?

#143
post #113

SMS-based 2FA is still vulnerable to phishing, but U2F is not. This has been solved for a while now, but I guess it's still a hassle for most folks to use them. I got my whole family Yubikeys a while back, and it seems to be going pretty well.

How do you backup access? The one thing that's stopped me from pulling the trigger on U2F is if that device is lost, stolen, or broken then I'm hosed, right? With standard 2FA, I have backup devices and codes that I can start restart from scratch if my phone is ever lost/stolen/broken.

Backup codes and (in my case) backup keys. In the corporate world, the backup codes can be generated and shared on-demand, or U2F temporarily disabled if ID can be verified another way.

Re: Passwordless: a different kind of hell?

#144

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

[deleted]

Re: Passwordless: a different kind of hell?

#145

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

Re: Passwordless: a different kind of hell?

#146
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Business don't want online shopping to be high-friction, but Thankfully consumer opinion is pushing more for security and less for making it as easy as possible to buy stuff online.

I'll happily take this shit-show cacophony of various 2fa methods and authentication types if nobody is stealing money from my bank account or ordering stuff on ebay on my behalf.

The flip side of this - is that if companies properly setup auth and allow you to use username+password (or passkeys) and a TOTP method then this is all basically copy/paste from your password manager or verify on your phone and the process is super easy.

Re: Passwordless: a different kind of hell?

#147
post #133

I can't login to a website from my desktop any more because I enabled passkeys, and my desktop doesn't have bluetooth to talk to my phone. Nor does anyone say what version of bluetooth is required

Why would you use a passkey manager that required a phone and BT? that's nuts.. 1password and Safari both handle syncing passkeys between all your devices - no device swapping needed.

Re: Passwordless: a different kind of hell?

#148

Earlier quoted context omitted.

> My phone sends all notifications to my desktop Is this a native phone feature or an app? You're lucky if that's the only place it sends notifications.

He uses KDE Connect. I use is as well. It is amazing, open source, and only sends notifications where you tell it to. https://kdeconnect.kde.org/

That's pretty cool; thanks.

Re: Passwordless: a different kind of hell?

#149

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

1Password can do this for you, and I assume many other password managers as well.

https://support.1password.com/one-time-passwords/

Re: Passwordless: a different kind of hell?

#150

My work just replaced our VPN app (which required a password) with something that they excitedly promised would provide us "passwordless login!" Lo and behold, it uses 2FA. Periodically I have to go get my phone[1] just to do my work. Way more friction than typing in the password. [1] No, I don't keep my phone on me all the time. It usually just sits in some random room at home.

Our VPN login used to be type your password, then accept the push notification from Duo. Now we decided push is insecure, so you now have to type "," as your password.

The starred-out password field plus my blank keycaps are a real test of my touch-typing ability.

Post reply on HN