Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

271–280 of 392 posts

Re: Passwordless: a different kind of hell?

#271

I think the industry, to some extent, already have reconsidered the session length, see [0] by Auth0 for example (even if it's obv. a PR piece). Nowadays my gut assumption when I use a service with really short sessions is that their security practices are probably questionable. I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insiste…

The thing that I find super frustrating about these short sessions is the lack of risk it's mitigating.

If it's expiring in a few minutes, presumably you're trying to protect against two things: (1) Session hijacking and (2) Unlocked computer.

Session hijacking is somewhat preventable via other means (eg: IP address tracking), but more importantly, in what case can a session be hijacked only 15 minutes later?

Someone walking away from an unlocked computer is an impossible problem for a app/site to solve. If an attacker has access to the PC, they can install malware that sniffs all traffic or passwords, and if the user saves their password(s) on their PC all of those are compromised anyway. This is a responsibility of the person responsible for the computer -- eg, the user and/or the IT admin.

When sessions/passwords expire in a time measured in days, I can't help but think they are basically saying "it's okay for an attacker to have access to this system for 89 days... but not 90!" The only valid argument I've ever heard for this is an attacker might be doing offline cracks of passwords -- but there's so many other fails involved there that I can't see how blindly expiring them is at all useful by comparison. Not to mention rotated passwords are very predictable[1] so it's unlikely to even mitigate the attack.

[1] https://www.sans.org/blog/the-debate-around-password-rotatio...

Re: Passwordless: a different kind of hell?

#272

Earlier quoted context omitted.

> Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? Because your hobby-project can emerge to be the backbone of someone's multibillion dollar-business, or a small gear in a million other projects, and you will get targeted for a supply-chain-attack.

Why should a multi-billion dollar business or a million other projects trust my code simply because GitHub made me 2FA to sign in? I may well decide the next push rewrites half the project in a breaking way on a whim or get an offer for $100k to give control of the project to the bad actor or just decide I don't like big corp anyway and be the bad actor myself. Turning providing source code into promising you'll foll…

I think it's more about GitHub's image and its self-imposed viewpoint that it needs to keep the software landscape secure. Requiring 2fa drastically reduces the number of ways a repo that is a building block for x% of a country's GDP gets compromised - now the only path is if the author intentionally hands over the repo/their account to a bad actor or e.g. posts their 2fa secrets on the internet for anyone to use.

Re: Passwordless: a different kind of hell?

#273
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Now imagine someone who has cognitive issues or is visually impaired trying to repeat this same process.

Re: Passwordless: a different kind of hell?

#275

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?

I love the Apple ecosystem, however I always have a low level of dread that someday I will somehow offend them and be permanently blacklisted. This is the main reason I've drawn the line at using their password manager or email - I use separate email and separate password manager so that in a worst case situation I don't get locked out of everything.

Re: Passwordless: a different kind of hell?

#276

Earlier quoted context omitted.

Their regular round pizzas are ok, but now that PizzaHut is gone, the Dominoes pan pizza is my go-to.

Pizza Hut is gone?

Nope.

I worked in a Pizza Hut delivery place when I was in college. I just took my son back for a campus visit and yeah, 30 years later, its still there - same location and save a few minor changes, the building still has the exact layout. A testament to whoever laid out the original floor plan.

Re: Passwordless: a different kind of hell?

#277

Earlier quoted context omitted.

You are right. However this cost should really be imposed on the multi-billion-dollar business and not on the author of the hobby app.

How should that work? Nobody knows who is using which part from which repo. And it's not just about big business. There are all kind of small communities and little apps, extensions, etc. with some small communities. Most of them don't even make money, but are juicy targets for some small fast money. Forcing everyone to raise their security and gain awareness about those things is a huge win for everyone, and only a…

> How should that work?

Fork and change the readme to reflect that this version is hardened for big business.

Re: Passwordless: a different kind of hell?

#278

I think the industry, to some extent, already have reconsidered the session length, see [0] by Auth0 for example (even if it's obv. a PR piece). Nowadays my gut assumption when I use a service with really short sessions is that their security practices are probably questionable. I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insiste…

Some of it depends on regulations and usage context. When I worked in healthcare, sessions were always short-lived. This may have been regulation-driven, but it's also based on the fact that often this software is being used on shared machines or in areas where unauthorized users are present (such as in patient rooms). While users are trained (very well, in my experience) to lock machines whenever they're unattended,…

I saw a demo like 15 or 20 years ago of a Sun thin client that used smart cards. You put your card in to any terminal, and nearly instantly your desktop session was live. Remove the card and it instantly disappears and locks.

That type of thing seems ideally suited to healthcare use, and we have such better devices now than whatever cards were used way back then. Amazing it's still Windows PCs deployed and secured with passwords.

Re: Passwordless: a different kind of hell?

#279
post #262

We have all been using physical keys for our homes and cars our whole lives. Physical U2F keys for digital authentication are basically the same level of convenience and actually very very secure: no shared secrets, not copyable, not forgeable, not vulnerable to phishing, etc. I don’t know why we haven’t all jumped on this solution to digital authentication

Theoretically it's a good solution, but practically it's an enormous task to migrate all existing digital infrastructure into a new hardware security paradigm.

Re: Passwordless: a different kind of hell?

#280

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

For a fairly similar experience for English speakers, see the sound that is written in Chinese pinyin as "sh" vs "x". They're two distinct sounds but will likely both register as "sh" to English speakers. Likewise "ch" and "q".
Post reply on HN