Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

311–320 of 392 posts

Re: Passwordless: a different kind of hell?

#311
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

I have a similar experience without Apple.

But.

Those synced passwords are a huge, juicy target. Someday, someone is going to get them. This process is a vulnerable mess.

Re: Passwordless: a different kind of hell?

#312

Earlier quoted context omitted.

They do a lot of interrupting the buyer with up-sell attempts. I'd have singled them out as notably bad , among fast food pizza chains, actually.

Interesting, which ones would be notably good in your opinion? To be fair we don’t have many fast food pizza chains in my country, it’s mostly dominos and a few small ones (with abysmal online order experience)

Well, I was maybe a little unfair because the competitors have at least partially “caught up”, but at one point, of Domino’s, Pizza Hut, Little Caesars, Godfather’s, plus a couple online pizza store SaaS used by smaller local chains, Domino’s was the only one that would interrupt me to make me click “no thanks” to some offer or other before proceeding, including during checkout. Multiple times per order, in their case—they’d do it once or twice in the checkout flow, plus sometimes after adding an item to the cart. I dropped them from the “oops we failed at getting dinner ready, what can be delivered and is cheap-ish?” rotation for a while over it.

They’re still the worst about it AFAIK but more of their competitors now do that at least once an order now, too, so the difference isn’t as large.

Re: Passwordless: a different kind of hell?

#313
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

The goal is to cover their asses for when data is stolen. It’s not a matter of “if”, it’s “when”, and they want to be able to point to every obnoxious POS practice they made standard to show they did their best. I’m not making any comments on whether this is good or bad, just that it, to me, explains a ton of the n behavior.

Re: Passwordless: a different kind of hell?

#314
post #294

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

This is slower than Apple Pay on the iPhone, I can assure you.

Well, yes (I also use Apple Pay when it’s available—best overall experience by a long shot) but it’s still quite fast and often involves no typing or copy-pasting.

Re: Passwordless: a different kind of hell?

#315

I have 743 login credentials (1984-present). Trusting 743 “randos on the internet” to safeguard “my” data, and give me access to use it. Insanity. Agent-Centric systems where I retain signing keys to authorize access to (and transactions using my) data are the way forward. A Key Fob (like you have for your car) is not onerous, and methods for recovery using trusted community members is practical. Holochain (and the H…

I mean, either those services need your data or they don't. I don't see how requiring you to upload or decrypt your data every time you want to use a service would be feasible for most things.

743 x:

- Addresses that are wrong

- Passwords stored (probably insecurely)

- Other personal data that can be stolen

If they "need it", they can be granted access to it (or a personally encrypted copy of it unique to them). Of course they can (and likely will) mis-manage even this data; Zero-Knowledge Proofs and Homomorphic Encryption should be used instead, where possible.

Remember, Public data written by an Agent are written to the DHT and are persistenly available, so "upload and decrypt" isn't really usually a thing in Holochain hApps.

So, if they want to make some non-repudiable claim under the auspices of "my account" (ie. claim agency on my behalf over some change of state, such as a "post" under my name, ...), then they can bloody well get me to sign such a state change with my private key. And, make all such data publicly available so that I (by my sole decision) can cease to use their service and take my data elsewhere.

Remember -- these are "randos on the internet" holding your data. Hundreds, or possibly even thousands of them including all the partners they sell your harvested data to, who are evidently incompetent in managing/securing it, and certainly don't care a whit about you and the sanctity of your data.

Re: Passwordless: a different kind of hell?

#316
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

>TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

I've done it in Aegis multiple times. They even allow you to export the 'database' (which iirc is just an encrypted json file)

Re: Passwordless: a different kind of hell?

#317
post #292
post #140

Earlier quoted context omitted.

Sure, so same problem. Less likely your yubikey will be stolen I guess, but less convenient too (something else to carry)

But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.

>But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed.

Half the time I choose for TOTP authentication over Yubikey because "Oh god it's in the living room I don't want to go get it."

I do have a backup key mind, but that's USB-C instead of A. Maybe I should make another USB A backup.

Re: Passwordless: a different kind of hell?

#318

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

I recall reading some interesting neurological research on this topic, about how phonemes are learned and accessed. The specific sounds stored in the brain are largely fixed by a pretty young age, making it almost impossible for adults to learn certain pronunciations that differ from anything they were exposed to as a child.

Re: Passwordless: a different kind of hell?

#319

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

I don’t know if it’s true or a common myth, but US soldiers in the Battle of the Buldge would ask possible spies baseball questions. Even if you were an American that didn’t like baseball, it was absolutely massive back then and would know some things about recent seasons.

Re: Passwordless: a different kind of hell?

#320

Earlier quoted context omitted.

Some of it depends on regulations and usage context. When I worked in healthcare, sessions were always short-lived. This may have been regulation-driven, but it's also based on the fact that often this software is being used on shared machines or in areas where unauthorized users are present (such as in patient rooms). While users are trained (very well, in my experience) to lock machines whenever they're unattended,…

I saw a demo like 15 or 20 years ago of a Sun thin client that used smart cards. You put your card in to any terminal, and nearly instantly your desktop session was live. Remove the card and it instantly disappears and locks. That type of thing seems ideally suited to healthcare use, and we have such better devices now than whatever cards were used way back then. Amazing it's still Windows PCs deployed and secured wi…

A previous employer (regional healthcare system) did exactly that: staff used their badges (along with another authentication factor, IIRC) to pull up their VDI instance on any client. This was just being rolled out ~8 years ago.
Post reply on HN