Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

361–370 of 392 posts

Re: Passwordless: a different kind of hell?

#361

Earlier quoted context omitted.

That's what I was thinking, which means you're not actually giving Apple your CC number.

My experience is that you can start the process by entering your credit card details, or use your camera to try fill them in for you. Apple then checks if your card issuer has ApplePay enabled and if so provisions a “virtual” card which is what is stored on the device’s Secure Enclave. I also just checked my banking app quickly which can initiate the adding of the card to wallet, showing the wallet’s add card screen…

> CC machines don’t actually have to support ApplePay specifically, as long as it supports tap to pay without insisting on a PIN, then ApplePay works with it. In essence your phone’s NFC exactly implements the same capabilities and protocols as NFC chips on normal credit cards.

IIRC it's not exactly the same. One user-facing example where things are different is that contactless payments with a regular credit card have a 50 € maximum. If there is a limit when paying with the iPhone, it's much higher.

I also seem to recall that the merchant's payment contract must support this, but I'll have to confirm with a colleague. Although Apple Pay support is very common where I live, it did happen a few times that some restaurant's terminal accepted VISA contactless but not Apple Pay.

I've also had a situation where my CC is set up to not allow payments outside my country. Payment with Apple Pay was denied as being "out of country", whereas the physical card worked fine. The store is from a big national chain, in the heart of the capital city.

Re: Passwordless: a different kind of hell?

#362
post #292
post #140

Earlier quoted context omitted.

Sure, so same problem. Less likely your yubikey will be stolen I guess, but less convenient too (something else to carry)

But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.

The problem I've always had with the two yubikey-model (except for cost an inconvenience of course) is that you can't really keep the second key in cold storage, because you need to enroll it to new accounts. That doesn't happen every day, but probably regularly enough that you can't keep in a bank vault or something.

On the other hand, you know the second one works and haven't spontaneously bitrotted.

My nerdy preferred version would have been (pre-passkey) to have a hardware token where the root secret is generated out-of-device and exist on e.g a paper backup or something. Then I could just buy a new hardware token and inject the same token if the device dies.

Re: Passwordless: a different kind of hell?

#363

You are a pavlovian dog, 2FA is just reporting to uncle Sam, It binds the biologic to the transaction, no plausible denieability. Great for securely buying Pizza but not so much for the future of humanity.

Its a joke how bad a future white people have ahead of them. Even their best here are hopelessly clueless about the situation they are entering into.

Re: Passwordless: a different kind of hell?

#364
post #343
post #275

Earlier quoted context omitted.

I love the Apple ecosystem, however I always have a low level of dread that someday I will somehow offend them and be permanently blacklisted. This is the main reason I've drawn the line at using their password manager or email - I use separate email and separate password manager so that in a worst case situation I don't get locked out of everything .

Don't worry, Google actually did lock me out of everything a few years ago and when you have the pleasure of using their wonderful services you're literally given no information and have to google (hehe) around for a form to send in a picture of your drivers license to which you will never receive a reply, your google account will remain "fraud blocked" and in 4 days you will have switched your entire life over to Ap…

This is why I don't mind paying the 5 euros a month for a Fastmail account. I don't send many emails but it's pretty much the key to the kingdom.

Re: Passwordless: a different kind of hell?

#365

Earlier quoted context omitted.

My experience is that you can start the process by entering your credit card details, or use your camera to try fill them in for you. Apple then checks if your card issuer has ApplePay enabled and if so provisions a “virtual” card which is what is stored on the device’s Secure Enclave. I also just checked my banking app quickly which can initiate the adding of the card to wallet, showing the wallet’s add card screen…

> CC machines don’t actually have to support ApplePay specifically, as long as it supports tap to pay without insisting on a PIN, then ApplePay works with it. In essence your phone’s NFC exactly implements the same capabilities and protocols as NFC chips on normal credit cards. IIRC it's not exactly the same. One user-facing example where things are different is that contactless payments with a regular credit card ha…

I’ve used ApplePay on CC machines which were clearly made before ApplePay even existed.

I’m pretty sure that the limit amount before PIN verification is required is embedded in the NFC, or checked online or something. Both my credit cards have limits of R500 (~26USD) after which it requires I enter my PIN after tapping it.

For one of my credit cards I’m able to pay it off with my other credit card and I have in the past tapped my iPhone to do so for payments over R50,000 (~2600USD), I don’t think there’s a limit.

However, the biggest grocery retail chain here initially had a very annoying “custom” rule on their CC machines where it would ignore the card limit and insist on asking for PIN for any payments over R500, which would cause ApplePay tap attempts to auto decline, they eventually fixed this.

The out of country issue sounds like a configuration issue with your bank or that particular merchant. My cards by default disallow use out of country and I’ve never had an issue tapping anywhere with ApplePay.

Re: Passwordless: a different kind of hell?

#366

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

iOS’s built in password manager iCloud Keychain does this automatically (at least on Safari).

Re: Passwordless: a different kind of hell?

#367
post #275

Earlier quoted context omitted.

How does that work if you want to get an android phone or Samsung tablet or windows laptop at some point?

I love the Apple ecosystem, however I always have a low level of dread that someday I will somehow offend them and be permanently blacklisted. This is the main reason I've drawn the line at using their password manager or email - I use separate email and separate password manager so that in a worst case situation I don't get locked out of everything .

I used to think the same - custom email domain, passwords managed by myself, but:

1) I’ve never ever heard Apple lock someone out of their Apple ID. Maybe they are obligated to do it for law enforcement in US but even none of that. Meanwhile I’ve heard a ton of stories of Google locking people out of their accounts.

2) The convenience of using Safari, with 2FA and passkeys set via iCloud Keychain is too good to ignore. Literally 1 click (passkeys) or 2 clicks at most, authenticated with Face ID.

So I’m using this setup rn. You can set custom domains with your iCloud email too.

Re: Passwordless: a different kind of hell?

#368

Earlier quoted context omitted.

Not to be argumentative, just wondering, has there been a case related to iCloud access that Apple has ever blacklisted someone? Certainly, I've heard of Meta and other companies doing not, but don't recall Apple outside of security confirmation issues people are having.

If you have 2FA and lose all your 2FA methods, and didn’t preplan by making a recovery key and storing it in a safe place you can find again… you can be screwed. It’s not a blacklist, but the net result is the same. I’m terrified of losing access to all my stuff because of forced 2FA I never signed up for. I get that it’s more secure, but it can be secure to the point of having unrecoverable data. All it would take i…

Setting up a recovery key for an Apple ID is optional. You can still recover your Apple ID. Apple will ask for information that can identify you, like previous iPhone passwords etc. If you have hit your head to a wall and can’t remember literally anything afair you are asked to wait some If you have recovery keys enabled, it’s a different story. Enabling screen clearly states that you can get locked out of your account without your recovery key. You can set up recovery accounts too, like those of your family members.

Re: Passwordless: a different kind of hell?

#369
Lots of people having lots of issues in the comments, I can't be the only one that has no problems with this.

I use bitwarden, it has my passwords and my TOTP codes in there, I have this on my phone and on my computers, everything auto fills. Other than that, I also have a hardware key for some services, all I need to do is click the hardware key when prompted. Some services only have email 2FA, but that's quite easy as well, I just get a notification and copy the code from there.

Doing a chain of 3 2FAs for 3 different services takes seconds.

For improved security this is easy, I'm not sure what everyone is on about.

Is this another case of complaining just for the sake of it?

Re: Passwordless: a different kind of hell?

#370
post #136

Earlier quoted context omitted.

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

In this case, how is eBay responsible for how PayPal and a bank handles things when they hand it off?

eBay is responsible whatever partner they are choosing. They knowingly picked PayPal. If the integration is terrible, they can work on this with their partner and maybe find a common way to establish trust.
Post reply on HN