Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

211–220 of 392 posts

Re: Passwordless: a different kind of hell?

#211
post #14

Earlier quoted context omitted.

Just turn on Passkeys on GitHub, then you don't need 2FA/TOTP. It's also faster.

My password manager autofilling will always be faster than any other option, especially one that requires me to pull out my phone, navigate to my authenticator app, switch to your app (which will only become more time-consuming as more sites require it), then type in the code by hand. The only thing that can compete with password managers on user experience is just actually remembering they're logged in instead of po…

> My password manager autofilling will always be faster than any other option

Passkeys will be faster.

Re: Passwordless: a different kind of hell?

#212

Earlier quoted context omitted.

You are right. However this cost should really be imposed on the multi-billion-dollar business and not on the author of the hobby app.

How should that work? Nobody knows who is using which part from which repo. And it's not just about big business. There are all kind of small communities and little apps, extensions, etc. with some small communities. Most of them don't even make money, but are juicy targets for some small fast money. Forcing everyone to raise their security and gain awareness about those things is a huge win for everyone, and only a…

> How should that work?

By the users of the software I publish noticing the license that states that while I hope this software is useful to them, it is provided with `"NO WARRANTY, NOT EVEN FOR FITNESS OF PURPOSE" and planning accordingly.

If you're an entity that wants to ensure that software you use from a source that you have approximately zero power over (and has explicitly provided NO warranty for that software) is and continues to be fit for purpose, you're going to have to inspect that software at a point in time, determine if it is fit for your purposes, and carefully inspect every future version of that software that you're considering using.

There really are no shortcuts. Requiring one to drink a Confirmation Can to log in doesn't change the math here.

Re: Passwordless: a different kind of hell?

#213

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

I stopped logging in into GitHub since then. My customers are using Bitbucket right now so the only reasons to log into GitHub would be to search the code of some project or opening an issue to one. Luckily I can search issues without being logged in and about opening issues, I feel a little bad but I don't open them anymore. It was my way to contribute to open source, it's gone because of too much friction.

[dead]

Re: Passwordless: a different kind of hell?

#214
I just opened a ticket with notion on mobile and plan on switching because I can’t use it for simple notes. This is the amount of steps it takes to login and you have to do it all the time:

* unlock your phone * tap notion * you're logged out - avoid the big login with x sso buttons, scan for and click the little text that's black on black labeled "login here with email" * type my email out (no autofill) * tap submit * exit app, open mail * find the notion email, usually it's right there other times, you must refresh constantly, sometimes it takes whole minutes because it's email * highlight as much of the password as you are able but not all of it because you can't due to the dashes * adjust highlighted text while holding down long enough to pop up the copy context window or memorize a cute phrase with dashes and type it out without making a mistake, 3 taps a dash (x4) because mobile keyboard layering * hit copy, exit app, open notion * press and hold in the textbox for the paste window or type it out * finally hit paste and submit * remember what you were trying to do quickly

Now add slow or glitchy(5g+) internet and it doesn’t work.

Even if you wanted to tie yourself permanently to an sso provider, a lot of the time, they too require re auth. If you have 2fa on (as you should) that's as many steps. The push for sso is also incredibly annoying. I’ve nearly deplatformed very intentionally.

Notion does a lot of funky things like refuse to build and offline mode which exacerbates this.

One other thing I don’t like about “passwordless” is biometric as a security feature instead of it as a convenience. 1Password removed passcode unlock on mobile in favor of faceid. Which if you don’t use it results in entering your full long password every time you use it, even if you just used it. Apparently I wasn’t the only one that complained because they restored the feature shortly after removing it. I unlock my friends phones while they are driving with faceid all the time. Too easy, not secure enough for the app that has most of my secrets.

Use 2fa, local passcodes that require reauth occasionally, and assume you are running on a locked device, if logging in from a new place maybe 3fa like Coinbase.

Re: Passwordless: a different kind of hell?

#215
post #6

Biometrics seem worse-is-better: you now have some unique identifier for me, which is totally swell until the inevitable DB breach. Which breech will likely be due to an Admin whoopsie of some sort. Because the people remain the weakest link.

Biometrics don’t require consent. Just hold up a friends phone towards their face.

Re: Passwordless: a different kind of hell?

#216

Earlier quoted context omitted.

FWIW this varies by background — Yemenite Jews still pronounce Ayin as Ghayin.

But there’s no letter for it in Hebrew?

Ayin (ע) is the letter, and was the original letter used in the spelling of Gaza — עזה is the oldest and original name of Gaza, for as long as it's had that name. The Hebrew alphabet hasn't changed letters in thousands of years, long predating other Semitic languages like Arabic which continue to use the Gh sound; ancient Hebrew is still easily understood in written form by modern Hebrew speakers — much more so than even Shakespeare is to modern English speakers. When people say "Hebrew lost..." what they mean is the pronunciation of letters changed, not that the alphabet changed (unlike e.g. English, which really has lost and gained letters even over very short periods). And in some cases the sounds were only lost in specific communities; Yemenite Jews have done a pretty good job retaining sounds, e.g. their pronunciation of ע, as well as ת. (Similarly, Ashkenazis' much-maligned pronunciation of ת is probably closer to the original than modern non-Yemenite Mizrahi/Sephardic pronunciation — although Yemenite is closer.)

The last time written Hebrew meaningfully changed was when the Paleo-Hebrew script was exchanged for Aramaic block script 2.5 thousand years ago, but even then, the replacement was 1:1 — ע was still Ayin, it was just written with a different character. And Paleo-Hebrew script has been around since the Bronze Age.

Re: Passwordless: a different kind of hell?

#217

anything other than username/email + password is stupid bullshit, i don't care what any cybersecurity nerd says.

Freakin Chipotle has mandatory 2FA. Blows my mind how thoroughly I need to authenticate myself to order a dang burrito.

Surprisingly, Chipotle is it's own layer of hell with it comes to auth. Every time I need to sign-in, I need to reset my password.

Re: Passwordless: a different kind of hell?

#218

Earlier quoted context omitted.

How are you populating non-SMS 2FA codes automatically?

1Password can do this for you, and I assume many other password managers as well. https://support.1password.com/one-time-passwords/

I use 1password but opt out of this feature. Just as described in the article masterpassword creates a single source of failure so I don't personally want to put more eggs in that basket.

Re: Passwordless: a different kind of hell?

#219

I have 743 login credentials (1984-present). Trusting 743 “randos on the internet” to safeguard “my” data, and give me access to use it. Insanity. Agent-Centric systems where I retain signing keys to authorize access to (and transactions using my) data are the way forward. A Key Fob (like you have for your car) is not onerous, and methods for recovery using trusted community members is practical. Holochain (and the H…

Key fob and the recovery method works for vehicles because it also requires physical access and knowing where that specific car is. It’s very easy for somebody to steal a specific car, even high end luxury car without after market mods if they can get to it.

This doesn’t work for the internet because anyone can access the target from anywhere.

We already do this to a degree with trusted CA centralization and there are recorded incidents (pretty frequently) of major breaches and state actors posing as various entities.

The stakes are also different, stealing a car is hard to do when it has physical security and has physical consequences. It’s also not worth a whole lot after because it’s hot. Stealing somebody’s identity is worth a whole lot more, hard to if even possible recover from and can be done remotely from anywhere.

I think centralization around brokers is a terrible idea. Look at Equifax, the audit after revealed it was only a matter of time before somebody utilized the multiple gaping completely negligent holes they had. The resulting fine for leaking every man, woman, and child’s ssn, birthdate, address, and drivers license was the equivalent of a few dollars to them.

Re: Passwordless: a different kind of hell?

#220

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?

If you go all-in on an ecosystem there's going to be pain if you decide to jump to another ecosystem. You can avoid some of that by using 1Password (I'm sure there are others as well). It integrates just fine with iOS.
Post reply on HN