Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

151–160 of 392 posts

Re: Passwordless: a different kind of hell?

#151

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

Case in point - Hebrew lost “Ghayin” way back in history so the Hebrew for Gaza is “’Aza” (with ‘Ayin)

FWIW this varies by background — Yemenite Jews still pronounce Ayin as Ghayin.

Re: Passwordless: a different kind of hell?

#152
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.

Re: Passwordless: a different kind of hell?

#153

Earlier quoted context omitted.

There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

Think about motivations for a moment.

The seller is motivated to make the buying process as easy, fast, and uncomplicated as possible. This is a direct correlation with how many things they sell, and in response how much money they make.

On the other hand - consumer opinion and regulation forces them to ensure that the buying process is secure, that someone else isn't buying things on your account, that they have proper logging of what goes on, etc.

The seller shouldn't "Fix" the buying experience by removing the security aspects of it. They should fix the buying experience by using modern authentication like passkeys and ensuring that their applications and sites support password managers.

Re: Passwordless: a different kind of hell?

#154

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

That, I don’t, but I only have those on work accounts anyway. None of my work stuff is set up to be as nice as my personal stuff, but that’s mostly outside my control.

Oh, wait: Steam has them I guess. Every so often (once every few months?) I have to type in one of their codes.

I did just check and I guess I could be doing this with non-sms codes if I added them to my password manager. If I had more than just Steam that used them, I’d do that.

Re: Passwordless: a different kind of hell?

#155

Earlier quoted context omitted.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across. Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)

That's because they need you to hurry up and pay for the terrible pizza before you change your mind.

(I too eat Domino's on the odd occasion the app doesn't take long enough for me to change my mind).

Re: Passwordless: a different kind of hell?

#156
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

2FAS [0] and I think Authy [1] as well have options for backing up your TOTP config

0: https://apps.apple.com/us/app/2fa-authenticator-2fas/id12177...

1: https://apps.apple.com/us/app/twilio-authy/id494168017

Re: Passwordless: a different kind of hell?

#157

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

> Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? Because your hobby-project can emerge to be the backbone of someone's multibillion dollar-business, or a small gear in a million other projects, and you will get targeted for a supply-chain-attack.

So implement those tighter security controls when they make sense. Don't force them on everyone when only a small fraction of cases are worthwhile.

Re: Passwordless: a different kind of hell?

#158
post #5

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

>Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable.

As time goes on I believe this less and less. I don't even think it's supported by the data. Spain or Sweden have way more thefts per capita than, say, Poland. Am I to believe a poor person is better of in Poland than in Spain or Sweden? They literally freeze to death sometimes.

I'm Spanish, I remember visiting Helsinki and finding toys in a wooden trunk in a small park for children. My first thought was "How is nobody stealing these?" and the second, immediate thought was how utterly sad the first one was. Am I to believe it's poverty pushing people to steal children's toys?

I think social cohesion is a factor often ignored, which is amazing in a way because it gets alluded to all the time, "They are tourists, who cares?", "Yeah but that guy is rich", "it's a supermarket", "They have insurance", "they are non-gypsies". Any of these has an implied "I don't care about that person because...". And this generates a feedback loop. It's harder to care about other people and have sympathy for them when you don't trust anyone not to steal your stuff if you leave it unattended for five minutes.

In retrospect, I do think those toys got "stolen" frequently, just because children grab stuff all the time and I'm sure it ended up lost more than once, but there must be an insistence to trust your fellow man, to trust that if a good is lost there must be a good reason. I don't think we have that trust anymore.

Re: Passwordless: a different kind of hell?

#160
post #92

Earlier quoted context omitted.

Healthcare should be universal and require almost no paperwork from the patient. Our current system is too bloated and either requires a job with good insurance or weeks/months of research into your options. Agencies like the DEA should be abolished and possession/use of drugs should not equal prison time or anything on your record. Of course, things like driving impaired are still punished because you're endangering…

Sweden has universal healthcare and education is free, but still Sweden suffers from massive crime wave. Sweden's welfare state is a left wing dream come true, however the bad news for the left is that it empirically disproves every left wing idea about crime and society.

You're getting downvoted, but the current situation in Sweden is a good example of why universal healthcare and free education are not enough.
Post reply on HN