Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

191–200 of 392 posts

Re: Passwordless: a different kind of hell?

#191
post #152
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.

Well pizza in particular often has a cash payment option, which I always use for that.

Re: Passwordless: a different kind of hell?

#192
Oh, this was disappointingly light on substance. It's an interesting musing on the history of passwords and the (very real) frustrations of modern authentication.

I thought it would have more depth though into the current state of various authentication schemes, in particular passwordless, which isn't actually mentioned at all. I find passwordless to be slightly less bumpy than various 2FA but still a genuine pain in the ass, to have to open up email in a second tab, wait for the email to come through, and then often follow a dubious link.

Re: Passwordless: a different kind of hell?

#193

Earlier quoted context omitted.

Only because you've standardized on their ecosystem and pre-given them all your data. This is not the future we were promised

You don’t have to give Apple your data. It uses information stored on device.

I’m a happy ApplePay user, but you absolutely do have to give them your (card) information upfront through the whole adding your card in the Wallet app.

That being said, I feel the parent’s viewpoint is naively idealistic, the payment industry is huge with many players and most attempts at new standards or interoperability are by people trying to get a cut of the action, no one is going to adopt a new standard unless they feel they absolutely have to.

ApplePay is pragmatic in that it largely hooks into the existing CC systems and thanks to Apple’s market size they have enough clout to convince people it’s worth the effort.

A whole new standard just for the “general good of the public” will never get any traction without regulation, and in places like the U.S. where bribery is essentially legal (so long as you call it lobbying), any new regulation like this faces an extreme uphill battle to being introduced except where someone standing to make lots of money is behind it.

Re: Passwordless: a different kind of hell?

#194

Earlier quoted context omitted.

Only because you've standardized on their ecosystem and pre-given them all your data. This is not the future we were promised

You don’t have to give Apple your data. It uses information stored on device.

Seems like parsing semantics. "Pre-given them" - are you giving it directly to apple.com? No. You're putting in your hardware, true. And... somehow... it makes it to all your other apple devices.

Re: Passwordless: a different kind of hell?

#195

Earlier quoted context omitted.

Case in point - Hebrew lost “Ghayin” way back in history so the Hebrew for Gaza is “’Aza” (with ‘Ayin)

FWIW this varies by background — Yemenite Jews still pronounce Ayin as Ghayin.

But there’s no letter for it in Hebrew?

Re: Passwordless: a different kind of hell?

#196

I think the industry, to some extent, already have reconsidered the session length, see [0] by Auth0 for example (even if it's obv. a PR piece). Nowadays my gut assumption when I use a service with really short sessions is that their security practices are probably questionable. I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insiste…

What gets me is that gmail login lasts...seemingly forever. And for most users, if their e-mail account were to get compromised, it's game over for everything they use, since so many services allow you to reset a password and possibly even remove 2FA with just e-mail verification.

What's even the attack scenario? Someone stealing a session token/cookie? If they can steal an expired one somehow, then there are good odds they could steal a current one, so the short session doesn't matter THAT much. I suppose another scenario is someone not logging out of their accounts on a public computer, but the type of person to do that likely uses "Password123!" as a password anyways.

Re: Passwordless: a different kind of hell?

#197

Earlier quoted context omitted.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across. Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)

They do a lot of interrupting the buyer with up-sell attempts. I'd have singled them out as notably bad, among fast food pizza chains, actually.

Re: Passwordless: a different kind of hell?

#198

Earlier quoted context omitted.

You don’t have to give Apple your data. It uses information stored on device.

I’m a happy ApplePay user, but you absolutely do have to give them your (card) information upfront through the whole adding your card in the Wallet app. That being said, I feel the parent’s viewpoint is naively idealistic, the payment industry is huge with many players and most attempts at new standards or interoperability are by people trying to get a cut of the action, no one is going to adopt a new standard unless…

> I’m a happy ApplePay user, but you absolutely do have to give them your (card) information upfront through the whole adding your card in the Wallet app.

Do you actually have to give them the card? Or is it only stored somehow on the phone? I wonder how this works exactly.

When I replaced my old iphone with a new one, I did the whole "transfer everything" dance. Waited around for two hours (didn't restore from icloud, but transferred from old to new), and still had to manually add my CCs to Apple Pay again.

Re: Passwordless: a different kind of hell?

#199
post #8

I understand the frustration with login systems, but why is the title "Passwordless: A Different Kind of Hell" if it doesn't talk about passwordless authentication, like passkeys, magic links, and biometrics?

> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…

Agree with the insights in your comment about biometrics != security, but I'd like to take a moment to nitpick a slight inaccuracy-- Asian faces don't actually look similar to each other, but they do look similar to a person/model that has been trained mostly on white faces. If the facial recognition model had been trained predominantly on Asian faces, then white faces would look similar to each other instead.

Reminder that the outputs of AI don't reflect some deeper truth about reality, just an extrapolation of the training data. Garbage in, garbage out.

Re: Passwordless: a different kind of hell?

#200
post #96
post #95

Earlier quoted context omitted.

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

By the way, the last time I checked using 3ds means that it's "impossible that the transaction was fraudulent" and thus you can't cancel it

Yikes, what happens if you've had your devices/credentials stolen? Are you held liable for the transaction without recourse?
Post reply on HN