Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

221–230 of 392 posts

Re: Passwordless: a different kind of hell?

#221

I think the industry, to some extent, already have reconsidered the session length, see [0] by Auth0 for example (even if it's obv. a PR piece). Nowadays my gut assumption when I use a service with really short sessions is that their security practices are probably questionable. I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insiste…

What gets me is that gmail login lasts...seemingly forever. And for most users, if their e-mail account were to get compromised, it's game over for everything they use, since so many services allow you to reset a password and possibly even remove 2FA with just e-mail verification. What's even the attack scenario? Someone stealing a session token/cookie? If they can steal an expired one somehow, then there are good od…

> ... since so many services allow you to reset a password and possibly even remove 2FA with just e-mail verification.

What is insane is that so many services allows to reset password and even 2FA without requiring any cooldown. The level of fail here is plain staggering. I don't really have words.

There are proper services out there who shall go out of their way to try to contact you, for example for 72 hours, before allowing any reset to happen. Some are going to say: "Wait, what!?, 72 hours!? I need to reset my 2FA NOW". They don't realize though that what they're really saying is: "I want bad guys to be able to reset my password/2FA instantly and log me out of everything they can in a split second". It's convenience vs security, once again.

As a sidenote I've read about a DB (in the EU) about SIM cards saying when they were swapped. And as a bank, you can check that DB and decide, for example, to refuse to let anyone change any setting if the SIM was swapped less than a week ago.

We need more people to think a bit about potential solutions instead of crying "but it's not convenient" and "bad guys shall find a way anyway".

Re: Passwordless: a different kind of hell?

#222
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

Use ravio on io’s, lets you copy, backup and duplicate them to other places.

Re: Passwordless: a different kind of hell?

#223
post #17

Earlier quoted context omitted.

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

That's just because they already have all of your identification, shipping, and payment information stored. Apple Pay isn't quite one-click fast, but it's damn near a miracle for one-off purchases from retailers you don't normally use. I've definitely made purchases I'd otherwise have walked away from (I'm pretty selective about who gets my credit card number).

Re: Passwordless: a different kind of hell?

#224
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

Years ago I had to do that sometimes, but I haven't gotten prompted to authenticate my credit card with my bank in quite a long time. I thought maybe it just went out of style, but I guess some people still use it.

Re: Passwordless: a different kind of hell?

#225

Earlier quoted context omitted.

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel. My credit card card [1] has fundamentally changed my online purchasing experience as it bri…

I've been using Privacy.com for this "create single use credit card" for years now. They make money via the interchange fees, afaik, and not by selling your data stream.

Do they still require that on your side it is a debit card?

Re: Passwordless: a different kind of hell?

#226

Earlier quoted context omitted.

You are right. However this cost should really be imposed on the multi-billion-dollar business and not on the author of the hobby app.

How should that work? Nobody knows who is using which part from which repo. And it's not just about big business. There are all kind of small communities and little apps, extensions, etc. with some small communities. Most of them don't even make money, but are juicy targets for some small fast money. Forcing everyone to raise their security and gain awareness about those things is a huge win for everyone, and only a…

Billion-dollar businesses can pay full-time professionals for support. They can hire staff or contract with a vendor. They can audit the free software they use or, like the good old days, pay for software whose vendors maintain it.

Or they can use hobbyist-written software for free, which is just fine, but don’t expect the hobbyist to support it for free.

Re: Passwordless: a different kind of hell?

#227

Earlier quoted context omitted.

Why would you submit yourself to using PayPal when you don't have to? Serious question.

Sometimes there's no choice, usually for international purchases. eBay used to also prefer PayPal somehow, idk how it is now. I know that some Etsy sellers are PayPal-only.

> eBay used to also prefer PayPal somehow

They owned PayPal for a while, so it was heavily promoted. It's still their first choice AFAICT.

Re: Passwordless: a different kind of hell?

#228

Earlier quoted context omitted.

Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Vendors (I'm looking at you, Audible!) constantly hide their account termination under layers of dark patterns. For awhile, I had several ghost subscriptions that I a.) didn't want and b.) couldn't cancel. My credit card card [1] has fundamentally changed my online purchasing experience as it bri…

>Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Paypal absolutely lets you stop recurring payments unilaterally on their side. I use Paypal for subscriptions wherever it's offered precisely for this reason. https://www.paypal.com/us/cshelp/article/what-is-an-automati...

Sort of? I don't think everything always shows up on https://www.paypal.com/myaccount/autopay/

I think it maybe only shows companies you had recent transactions with.

In 2023, I had a fraudulent $0.99 Paypal Automatic Payment for "Domain Name Forwarding - Renewal" from a company (DomainsPricedRight/OwnMyDomain aka GoDaddy) that I last did business with in 2005. Yes, 18 years prior.

I was able to 'deactivate' the 'subscription' on the Paypal site after I noticed the charge but I don't think automatic payments existed on Paypal in 2005 and I'd certainly never signed up for it.

The original 2005 business I did was a one time domain purchase that was transferred to another registrar within a year.

It was real fun to also see on Paypal that I could have been fraudulently charged up to $10,000.

It's kind of scary to think that any company I've done a Paypal transaction with could maybe do the same thing (or any of the companies that eventually acquire their merchant accounts...)

Re: Passwordless: a different kind of hell?

#229
post #8

I understand the frustration with login systems, but why is the title "Passwordless: A Different Kind of Hell" if it doesn't talk about passwordless authentication, like passkeys, magic links, and biometrics?

> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…

biometrics are used in combination with a specific device. same as a PIN (you can't withdraw money from an ATM with just a PIN, you need the chipped card + your PIN)

i can't go up to just any computer and log into my bank with my face

you would have to possess my phone and then deepfake me

i am comfortable with this security posture because the convenience of face id allows me to use long random passwords with frequent rollover which I never have to type

if i lose my phone I can remotely disable it

this is all much less of a crime to me than any service that allows password reset over SMS which is a much more well trodden vulnerability.

Re: Passwordless: a different kind of hell?

#230

Earlier quoted context omitted.

Sometimes there's no choice, usually for international purchases. eBay used to also prefer PayPal somehow, idk how it is now. I know that some Etsy sellers are PayPal-only.

> eBay used to also prefer PayPal somehow They owned PayPal for a while, so it was heavily promoted. It's still their first choice AFAICT.

There's that, and also I remember some sellers were PayPal-only or at least preferred it back in the day, but that's not a thing anymore.
Post reply on HN