Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

251–260 of 392 posts

Re: Passwordless: a different kind of hell?

#251
post #152
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.

Then they store your credit card info in a database and leak it some time next year.

Re: Passwordless: a different kind of hell?

#252

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

Personally, I think that they simply don't like to be go to free storage for all of our personal or hobby or open spurce projects.

This way, free users are less likely to use github while paying corporations will stay.

Re: Passwordless: a different kind of hell?

#253

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?

It doesn't, but I've used Apple stuff for going on 25 years now and it is doubtful I will care to move to something different any time soon, so it works for me.

Always the tradeoff with Apple is choice and flexibility versus a seamless and pleasant user experience.

Re: Passwordless: a different kind of hell?

#254

Earlier quoted context omitted.

1Password can do this for you, and I assume many other password managers as well. https://support.1password.com/one-time-passwords/

I use 1password but opt out of this feature. Just as described in the article masterpassword creates a single source of failure so I don't personally want to put more eggs in that basket.

I keep my unimportant 2FA in 1Password and the really important one’s (e-mail, domains, etc) in a separate 2FA app.

If someone has pwned my 1Password I don’t really care if they log on to my Discord or order a limited amount of crap on Amazon because I am in much deeper shit at that point.

Re: Passwordless: a different kind of hell?

#255

Earlier quoted context omitted.

Amazon is probably the lowest and will stay so for a while I guess. They didn't cling to their one click patent for nothing.

Dominos has the best checkout experience I ever experienced online. Nothing can beat it IMO, at least nothing I came across. Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)

In my city they used to have a 25 minute (!) click to door delivery guarantee. Extremely impressive.

Re: Passwordless: a different kind of hell?

#256

Earlier quoted context omitted.

> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…

> Face unlocks can be fooled by pictures Isn't that only Android (and maybe only older models)? Doesn't iOS use a LIDAR sensor instead of the camera?

Correct. Depending on the phone, on Android the face unlock will not work with a 2D image. Perhaps only on cheaper phones.

On Windows for example you can't even have face unlock without a sensor that will provide 3D details so most laptops don't support Windows Hello.

Re: Passwordless: a different kind of hell?

#257

Earlier quoted context omitted.

> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…

Agree with the insights in your comment about biometrics != security, but I'd like to take a moment to nitpick a slight inaccuracy-- Asian faces don't actually look similar to each other, but they do look similar to a person/model that has been trained mostly on white faces. If the facial recognition model had been trained predominantly on Asian faces, then white faces would look similar to each other instead. Remind…

[dead]

Re: Passwordless: a different kind of hell?

#258

Earlier quoted context omitted.

The iOS Keychain already supports TOTP.

Ah yeah, it's hidden away a little cause they don't call it TOTP and you need to manually copy codes into your settings app. Gonna see if I can set it up on Mac cause that's where I'll actually maybe need it.

Set up should be simpler than needing to manually copy codes into your settings app.

When a QR code is present on screen that resolves to a TOTP seed, an additional context menu option should be present to "Add Verification Code in Passwords" or "Set Up Verification Code" or similar.

Here's a screenshot I nabbed from a way-too-wordy article on the subject: https://tidbits.com/uploads/2021/10/Add-Verification-Code-15...

Re: Passwordless: a different kind of hell?

#259
post #14

Earlier quoted context omitted.

Just turn on Passkeys on GitHub, then you don't need 2FA/TOTP. It's also faster.

I don't see how Passkeys eliminates the need for 2FA. Seems to me, and I may not understand it, but it seems to me that Passkeys are more of a way to eliminate having to constantly re-enter you password, but do not eliminate passwords. For example, if I set up a Passkey, that's bound to a specific machine/browser/phones/whatever. But if I log in from another device, there are no Passkeys, so I just need to use my pas…

> I don't use any syncing system, I'm not on iCloud, or use apps, or anything like that, so there's no mechanic for distribution of passkeys. Plus that wouldn't work if I wanted to log from my friends laptop, or something like that.

iOS and Android can also just keep local Passkeys where you scan a QR code, though of course if you don't backup anything anywhere you will always have a redundancy problem with any 2FA mechanism.

Passkeys are supposed to not be a single authenticator either, so you can enroll another Phone or a Yubikey (or also your local TPM, binding to your user account, for convenience), but not all services support that in practice.

Re: Passwordless: a different kind of hell?

#260
post #17

Earlier quoted context omitted.

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

I’m not even embarrassed to say last night I went to check out, saw there wasn’t an Apple Pay option, waited through about 2 minutes of waiting for the credit card details panel to open before bailing.

If it took two minutes for a credit card form to open up that's clearly a site problem, and would likely have been just as broken even with an Apple Pay option.
Post reply on HN