Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

351–360 of 392 posts

Re: Passwordless: a different kind of hell?

#351
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

The involuntary signup for two factor you didn't want is incredibly annoying. Especially when initiated by a bank or similar financial institution with no warning.

"BTW, for your own safety, we implemented two factor on your account, and tied it to your old phone. Wait, you don't have that phone anymore, cause it was something like a 10 yr old retirement that you never obsessively check? And we didn't give you the option for an email? Or even warn you? Too bad. We now no longer accept logins for your own money."

Re: Passwordless: a different kind of hell?

#352

Earlier quoted context omitted.

> so an Ephraimites soldier was literally incapable of pronouncing the word "correctly". And, importantly, they would not even have realized that they were saying it wrong, because they would have been unable to hear the difference. As a modern example: I have an acquaintance from Tonga. At some point she got very frustrated with the people around her who didn't understand what she meant by the "rittel bin". She fina…

I learned French as an adult, and I cannot at all hear the difference between the words "rue" and "roue." People tell me there's a difference and they try to sound it out to me, but each time they do, I just have to trust that they aren't saying the same thing twice.

There are native-English dialect groups which make no distinction between the vowels in 'pin' and 'pen'.

For all I rib my wife about falling on the other side of that line, it took my American ear a long time to hear UK-dialect(s) distinctions between 'Mary', 'merry', and 'marry', and still a fair bit of concentration to reproduce them!

Re: Passwordless: a different kind of hell?

#353
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

Use Aegis.

Re: Passwordless: a different kind of hell?

#354
post #304

Earlier quoted context omitted.

What a weird comparison. Embezzling is abusing a position of trust to become a thief. Who was abused if someone privately consumed drugs?

If you believe that privately consuming drugs doesn't reflect negatively on someone, you can hire them. If you don't hire them and nobody else hires them either, the drug use is keeping them from being hired. It's misleading to claim that the conviction keeps them from being hired rather than the drug use.

That's nonsense. If you have a private drug habit and don't get caught, that won't come up on a background check. Lots of people consume recreationally without being addicts or messing up the rest of their lives. A conviction (sometimes just an arrest record) that comes up on a background check will automatically put applicants in the reject pile in many jobs. This is such a common problem some US states (eg California) have passed laws to prevent employers demanding this information of applicants.

Re: Passwordless: a different kind of hell?

#355

Earlier quoted context omitted.

You don’t have to give Apple your data. It uses information stored on device.

I’m a happy ApplePay user, but you absolutely do have to give them your (card) information upfront through the whole adding your card in the Wallet app. That being said, I feel the parent’s viewpoint is naively idealistic, the payment industry is huge with many players and most attempts at new standards or interoperability are by people trying to get a cut of the action, no one is going to adopt a new standard unless…

I agree. No naive ideals here. There should be a standard that makes it easy and private for the consumer. Doesn’t mean it will happen.

Re: Passwordless: a different kind of hell?

#356
post #96
post #95

Earlier quoted context omitted.

It's 3ds, I don't know if it's because of some regulation but with my current (european) bank it's always compulsory. And a credit card I've got recently also asks for a second code, after the 3ds code.

By the way, the last time I checked using 3ds means that it's "impossible that the transaction was fraudulent" and thus you can't cancel it

I've heard it presented more as that the merchant isn't on the hook for a chargeback because they did the "best practice" in terms of preventing it.

Re: Passwordless: a different kind of hell?

#357

Earlier quoted context omitted.

One a thief always a thief, there's a reason it was punished so severely throughout history. Theft has the highest recidivism rate too[1]. You can never trust someone who has stolen again, thieves are the scum of the earth and only hurt good people. [1] https://www.gov.uk/government/statistics/proven-reoffending-...

Hmmm maybe there is a good reason they chop off thieves' hands in Islam...

Jesus guys

Re: Passwordless: a different kind of hell?

#358

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

Anyone else feels that the double clicking of the side button doesn't feel ergonomic? It doesn't feel right to me when doing it. I end up holding it like a gun, and then double clicking it, as in the default pose of holding a phone, my thumb is unable to double click.

It's a habit to take I guess. Moving the mouse around feels very weird for people who have never used it before (yes, those exist).

Re: Passwordless: a different kind of hell?

#359

Earlier quoted context omitted.

Then they store your credit card info in a database and leak it some time next year.

It's pretty annoying that they load all this pain and suffering onto the user who's just trying to make a purchase, when the company's database is often the weakest link.

This is fascinating to me. Why do we have to go through all these hoops with the bank and somehow, when the credit card # is eventually and ineluctably leaked, the thieves have no problem using it to make purchases, whiteout going through all these 3FA etc.

How is that possible?

Re: Passwordless: a different kind of hell?

#360

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

KeepassXC can act as a TOTP client and can fill it just like it can do passwords.
Post reply on HN