Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

241–250 of 392 posts

Re: Passwordless: a different kind of hell?

#241

Earlier quoted context omitted.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across. Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)

Off topic: once worked at a company that built a "domino tracker" of some security service we were installing on customer hosts. The company spent more time and money on the tracker than the service installation. The installation tooling failed most of the time and threw errors out for "ephemerality". Good times.

Re: Passwordless: a different kind of hell?

#242

Earlier quoted context omitted.

> I’m a happy ApplePay user, but you absolutely do have to give them your (card) information upfront through the whole adding your card in the Wallet app. Do you actually have to give them the card? Or is it only stored somehow on the phone? I wonder how this works exactly. When I replaced my old iphone with a new one, I did the whole "transfer everything" dance. Waited around for two hours (didn't restore from iclou…

It's stored on your phone in the secure enclave.

That's what I was thinking, which means you're not actually giving Apple your CC number.

Re: Passwordless: a different kind of hell?

#243

Earlier quoted context omitted.

You don’t have to give Apple your data. It uses information stored on device.

Seems like parsing semantics. "Pre-given them" - are you giving it directly to apple.com? No. You're putting in your hardware, true. And... somehow... it makes it to all your other apple devices.

Apple Pay is one of the (few) things where that is not the case. New phone = manually re-adding cards to Apple Pay. Get an Apple Watch? It does not get your Apple Pay info until you manually add them to the watch.

Re: Passwordless: a different kind of hell?

#244

Earlier quoted context omitted.

Freakin Chipotle has mandatory 2FA. Blows my mind how thoroughly I need to authenticate myself to order a dang burrito.

Surprisingly, Chipotle is it's own layer of hell with it comes to auth. Every time I need to sign-in, I need to reset my password.

McDonald's, Taco Bell, and Dominos apps seem to be the best, everything else ends up in login hell (though I suspect I have two McDonald's and Taco Bell accounts from before they added Apple login).

Some are literally so bad I just won't use them anymore.

All most of these things need is basic authentication, set some long-lived whatever it is based on the Secure Enclave, and if then don't allow seeing the charge method or changing the delivery address without requiring some second factor. You don't need full bank-level security for a burrito (amusingly enough, my bank security is more based on normal things than the burritos are).

Re: Passwordless: a different kind of hell?

#245
post #228

Earlier quoted context omitted.

>Payment gateways (paypal, apple, google), in general, do NOT let you cancel individual services and are linked to your CC. Paypal absolutely lets you stop recurring payments unilaterally on their side. I use Paypal for subscriptions wherever it's offered precisely for this reason. https://www.paypal.com/us/cshelp/article/what-is-an-automati...

Sort of? I don't think everything always shows up on https://www.paypal.com/myaccount/autopay/ I think it maybe only shows companies you had recent transactions with. In 2023, I had a fraudulent $0.99 Paypal Automatic Payment for "Domain Name Forwarding - Renewal" from a company (DomainsPricedRight/OwnMyDomain aka GoDaddy) that I last did business with in 2005 . Yes, 18 years prior. I was able to 'deactivate' the 'su…

I believe that this is the more reliable URL (it's certainly the one I provide to Ardour subscribers):

https://www.paypal.com/cgi-bin/webscr?cmd=_manage-paylist

[ EDIT: which redirects to the one you cited, so forget my attempt to be less wrong ]

Re: Passwordless: a different kind of hell?

#246
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Good job passing the dice roll to stay out of the special hell where the SMS code never arrives.

Not sure if this is your experience, but when I broke a chunk out of my Samsung screen and then went to AT&T to trade for another Samsung, keeping the same phone number, I can't receive a two factor security code by text. Even after calling AT&T and being told that the traded in phone is "dead". So now I have to receive a call for security codes.

Re: Passwordless: a different kind of hell?

#247

Earlier quoted context omitted.

It's the Google Authenticator app's fault. The most popular TOTP app probably, and for a long time, they were saying it's intentionally designed not to let you copy the codes. Now you can, but there are lots of pitfalls and vague documentation. I'm not convinced that TOTP is a user-friendly design to begin with, but it didn't have to be this bad. I don't fw TOTP now. There are other apps, but I'm done. I'll only use…

The iOS Keychain already supports TOTP.

Ah yeah, it's hidden away a little cause they don't call it TOTP and you need to manually copy codes into your settings app. Gonna see if I can set it up on Mac cause that's where I'll actually maybe need it.

Re: Passwordless: a different kind of hell?

#249

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?

you don't, that's the whole apple strategy lock-in your average younger, non technical person so much that they find it 'an ick' to have to interact with an android user.

Re: Passwordless: a different kind of hell?

#250
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

That's why I store them in Bitwarden.
Post reply on HN