I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…
Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.
Passwordless: a different kind of hell?
251–260 of 392 posts
Re: Passwordless: a different kind of hell?
#252We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…
This way, free users are less likely to use github while paying corporations will stay.
Re: Passwordless: a different kind of hell?
#253Earlier quoted context omitted.
Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…
How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?
Always the tradeoff with Apple is choice and flexibility versus a seamless and pleasant user experience.
Re: Passwordless: a different kind of hell?
#254Earlier quoted context omitted.
1Password can do this for you, and I assume many other password managers as well. https://support.1password.com/one-time-passwords/
I use 1password but opt out of this feature. Just as described in the article masterpassword creates a single source of failure so I don't personally want to put more eggs in that basket.
If someone has pwned my 1Password I don’t really care if they log on to my Discord or order a limited amount of crap on Amazon because I am in much deeper shit at that point.
Re: Passwordless: a different kind of hell?
#255Earlier quoted context omitted.
Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.
Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across. Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)
Re: Passwordless: a different kind of hell?
#256Earlier quoted context omitted.
> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…
> Face unlocks can be fooled by pictures Isn't that only Android (and maybe only older models)? Doesn't iOS use a LIDAR sensor instead of the camera?
On Windows for example you can't even have face unlock without a sensor that will provide 3D details so most laptops don't support Windows Hello.
Re: Passwordless: a different kind of hell?
#257Earlier quoted context omitted.
> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…
Agree with the insights in your comment about biometrics != security, but I'd like to take a moment to nitpick a slight inaccuracy-- Asian faces don't actually look similar to each other, but they do look similar to a person/model that has been trained mostly on white faces. If the facial recognition model had been trained predominantly on Asian faces, then white faces would look similar to each other instead. Remind…
Re: Passwordless: a different kind of hell?
#258Earlier quoted context omitted.
The iOS Keychain already supports TOTP.
Ah yeah, it's hidden away a little cause they don't call it TOTP and you need to manually copy codes into your settings app. Gonna see if I can set it up on Mac cause that's where I'll actually maybe need it.
When a QR code is present on screen that resolves to a TOTP seed, an additional context menu option should be present to "Add Verification Code in Passwords" or "Set Up Verification Code" or similar.
Here's a screenshot I nabbed from a way-too-wordy article on the subject: https://tidbits.com/uploads/2021/10/Add-Verification-Code-15...
Re: Passwordless: a different kind of hell?
#259Earlier quoted context omitted.
Just turn on Passkeys on GitHub, then you don't need 2FA/TOTP. It's also faster.
I don't see how Passkeys eliminates the need for 2FA. Seems to me, and I may not understand it, but it seems to me that Passkeys are more of a way to eliminate having to constantly re-enter you password, but do not eliminate passwords. For example, if I set up a Passkey, that's bound to a specific machine/browser/phones/whatever. But if I log in from another device, there are no Passkeys, so I just need to use my pas…
iOS and Android can also just keep local Passkeys where you scan a QR code, though of course if you don't backup anything anywhere you will always have a redundancy problem with any 2FA mechanism.
Passkeys are supposed to not be a single authenticator either, so you can enroll another Phone or a Yubikey (or also your local TPM, binding to your user account, for convenience), but not all services support that in practice.
Re: Passwordless: a different kind of hell?
#260Earlier quoted context omitted.
Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.
I’m not even embarrassed to say last night I went to check out, saw there wasn’t an Apple Pay option, waited through about 2 minutes of waiting for the credit card details panel to open before bailing.