We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…
I stopped logging in into GitHub since then. My customers are using Bitbucket right now so the only reasons to log into GitHub would be to search the code of some project or opening an issue to one. Luckily I can search issues without being logged in and about opening issues, I feel a little bad but I don't open them anymore. It was my way to contribute to open source, it's gone because of too much friction.
Passwordless: a different kind of hell?
341–350 of 392 posts
Re: Passwordless: a different kind of hell?
#342Earlier quoted context omitted.
Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.
Only because you've standardized on their ecosystem and pre-given them all your data. This is not the future we were promised
Re: Passwordless: a different kind of hell?
#343Earlier quoted context omitted.
How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?
I love the Apple ecosystem, however I always have a low level of dread that someday I will somehow offend them and be permanently blacklisted. This is the main reason I've drawn the line at using their password manager or email - I use separate email and separate password manager so that in a worst case situation I don't get locked out of everything .
Then 1 yr later a hn thread will remind you to try to log into your google SSO and.. bam it works. And you still have no idea why ALL of your g servces (domains, email, gphone, etc) were disconnected a year ago.
Re: Passwordless: a different kind of hell?
#344Earlier quoted context omitted.
> biometrics Biometrics are a convenience feature, not a security feature. Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking. But the worst part ab…
Agree with the insights in your comment about biometrics != security, but I'd like to take a moment to nitpick a slight inaccuracy-- Asian faces don't actually look similar to each other, but they do look similar to a person/model that has been trained mostly on white faces. If the facial recognition model had been trained predominantly on Asian faces, then white faces would look similar to each other instead. Remind…
I think this should be “more similar than other groups” rather than simply “similar”. Even then I think it’s possible that some groups have more loci with higher diversity for facial features. That’s not even getting to epigenetic and environmental elements.
I think the deeper truth is in your final paragraph: facial similarity is in the eye of the beholder.
Re: Passwordless: a different kind of hell?
#345Earlier quoted context omitted.
What I do is when I receive a QR code to set up TOTP while creating a new account is to take a screenshot of that code and save an encrypted copy of that screenshot. Then it is just part of my ordinary data backed up as part of my normal backups. If I ever want to set up a TOTP app on a new device it is not hard to decrypt all my saved QR codes, open them all at the same time in Preview on my Mac, select the option t…
Why use a QR code reader app instead of the built in camera app? Personally, I email the backup codes to myself. Yes it's less secure in theory, but the only time I'm using totp is against my will.
The QR code is on the screen of my desktop Mac. The camera is right above the screen facing me and can't see what is on the screen.
I could read it with the built in camera app on my iPhone or iPad, but that just tells me it is a QR code for the TOTP authenticator app I use and opens that if I tap. I don't see a way to get it to tell me the content of the QR code in text form. Even if it had a way that would be on the phone and I want the text to save it on the Mac.
Re: Passwordless: a different kind of hell?
#346Earlier quoted context omitted.
This looks like a ridiculous strawman's argument. For example, there's a large difference between stealing food from a produce stand (which I would certainly do if the alternative was to starve) and "carjacking people." I agree with the OP - as a society, we should look more at aligning incentives rather than instilling morals. Another huge area this comes up is the war on drugs - if you're caught with drugs, we slap…
Why don’t thieves stop being thieves after they can afford food?
Re: Passwordless: a different kind of hell?
#347Earlier quoted context omitted.
Why use a QR code reader app instead of the built in camera app? Personally, I email the backup codes to myself. Yes it's less secure in theory, but the only time I'm using totp is against my will.
> Why use a QR code reader app instead of the built in camera app? The QR code is on the screen of my desktop Mac. The camera is right above the screen facing me and can't see what is on the screen. I could read it with the built in camera app on my iPhone or iPad, but that just tells me it is a QR code for the TOTP authenticator app I use and opens that if I tap. I don't see a way to get it to tell me the content of…
Re: Passwordless: a different kind of hell?
#348I never worried about losing access to it.
Until the day I enabled 2FA on it.
You can't get my personal e-mail password out of my mind but you can get my smart phone out of my hand.
I've used half my backup codes by now.
Re: Passwordless: a different kind of hell?
#349Earlier quoted context omitted.
This looks like a ridiculous strawman's argument. For example, there's a large difference between stealing food from a produce stand (which I would certainly do if the alternative was to starve) and "carjacking people." I agree with the OP - as a society, we should look more at aligning incentives rather than instilling morals. Another huge area this comes up is the war on drugs - if you're caught with drugs, we slap…
>if you're caught with drugs, we slap you with a felony that ensures you can't get a real job... pushing you right back to drugs. I could say the same thing for any sort of crime. If you're an accountant, and you get put in jail for embezzling, that conviction is going to prevent you from getting another job as an accountant. While there have been a few controversies about jobs that the law excludes felons from, in a…
It has been my anecdotal observation that it is more common for small, local businesses to "look past" prior convictions when hiring and be more willing to take chances on their neighbors.
Large corporations with big HR and legal departments typically have a dimmer view of things however.
Right or wrong, it is harder to get a job with a past conviction. Without a job, it is difficult to earn a living, feed and house yourself and your family. When people are desperate and unable to survive through legal means, they resort to whatever it takes to survival. It's human nature.
Re: Passwordless: a different kind of hell?
#350Earlier quoted context omitted.
What a weird comparison. Embezzling is abusing a position of trust to become a thief. Who was abused if someone privately consumed drugs?
If you believe that privately consuming drugs doesn't reflect negatively on someone, you can hire them. If you don't hire them and nobody else hires them either, the drug use is keeping them from being hired. It's misleading to claim that the conviction keeps them from being hired rather than the drug use.
If I'm understanding you correctly, you're arguing that a drug user is less employable (perhaps because you believe drug users are untrustworthy or unreliable), and this is the reason they aren't hired.
But a conviction for a drug crime years ago does not mean someone is a drug user today. It is the conviction, not drug use, keeping them from being hired. A drug test would make more sense if you want to determine whether someone is a current drug user.
And besides, without the conviction you may be unaware of their drug use. If someone has a drug habit, but nobody can tell, what exactly is the problem? There are plenty of "functioning alcoholics" in the workforce.