Earlier quoted context omitted.
Order pizza, pay with virtual card. Payment provider needs 3FA+Captcha, one of the factors is email which is another 2FA challenge. Disclosing the card details once logged in prompts for another 2FA, finally VISA also challenges you with a recent payment question. Insanity.
Then they store your credit card info in a database and leak it some time next year.
Passwordless: a different kind of hell?
371–380 of 392 posts
Re: Passwordless: a different kind of hell?
#372Earlier quoted context omitted.
Don't worry, Google actually did lock me out of everything a few years ago and when you have the pleasure of using their wonderful services you're literally given no information and have to google (hehe) around for a form to send in a picture of your drivers license to which you will never receive a reply, your google account will remain "fraud blocked" and in 4 days you will have switched your entire life over to Ap…
This is why I don't mind paying the 5 euros a month for a Fastmail account. I don't send many emails but it's pretty much the key to the kingdom.
Re: Passwordless: a different kind of hell?
#373We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…
With my one not really as you still have to enter a simple password to do anything - six letters, no dumb requirements for capitals and odd symbols.
There is something to be said for simple passwords that people can actually remember. They don't work in situations where hackers can try loads of attempts electronically but where you have to type them if they are quite good really.
Re: Passwordless: a different kind of hell?
#374Earlier quoted context omitted.
Sure, so same problem. Less likely your yubikey will be stolen I guess, but less convenient too (something else to carry)
But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
There's then the whole mobile problem -- yubikeys are perhaps fine with my laptop, but how about when I'm using a mobile and my laptop is in my bag, or at home?
And OK, lets say I solve all that. How do I add a second key?
The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons. It also ties in well with my phone -- if I get an SMS with a number 123456, it appears as an automatic insert option on the form, no need to go to another app to copy a number and switch back to paste.
TOTP and Yubikeys do not match the usability of SMS.
Re: Passwordless: a different kind of hell?
#375Earlier quoted context omitted.
But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.
> But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port. There's then the whole mobile problem -- yubikeys are perhaps fine with my laptop, but how about when I'm using a mobile and my laptop is in my bag, or at home? And OK…
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
It's difficult, though not impossible, to break your USB port with a Yubikey due to its shape. It's not a regular USB plug and will come out quite easily. but how about when I'm using a mobile and my laptop is in my bag, or at home?
USB-C and NFC variants are quite common. And OK, lets say I solve all that. How do I add a second key?
The same way you add the first--most of the time, you have to scan a QR code. You can scan it more than once. The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons.
I'm not giving you my phone number, and mobile providers are known to send replacement SIM cards to random strangers if they ask nicely.Re: Passwordless: a different kind of hell?
#376Earlier quoted context omitted.
But it's a key though. It goes on the keychain. Unless you don't carry around keys either, in which case yes, that would be very inconvenient indeed. Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.
The problem I've always had with the two yubikey-model (except for cost an inconvenience of course) is that you can't really keep the second key in cold storage, because you need to enroll it to new accounts. That doesn't happen every day, but probably regularly enough that you can't keep in a bank vault or something. On the other hand, you know the second one works and haven't spontaneously bitrotted. My nerdy prefe…
Re: Passwordless: a different kind of hell?
#377Earlier quoted context omitted.
I learned French as an adult, and I cannot at all hear the difference between the words "rue" and "roue." People tell me there's a difference and they try to sound it out to me, but each time they do, I just have to trust that they aren't saying the same thing twice.
There are native-English dialect groups which make no distinction between the vowels in 'pin' and 'pen'. For all I rib my wife about falling on the other side of that line, it took my American ear a long time to hear UK-dialect(s) distinctions between 'Mary', 'merry', and 'marry', and still a fair bit of concentration to reproduce them!
Re: Passwordless: a different kind of hell?
#378Earlier quoted context omitted.
There are things you can do to make it easier. My phone sends all notifications to my desktop, and I have an app on the phone that creates a notification when it recognises a code in the SMS, so all I need do is double click on the notification (to select the entire "word" that is the code) then paste into the site I am verifying to. There are also authenticator browser extensions so you do not have to use a phone ap…
We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.
Of the two applications I use for the SMS flow, one is generally useful to have anyway. The authenticator extension or an app is absolutely necessary for this type of 2FA and the alternative to some app is to not use 2FA at all or use SMS authentication.
Re: Passwordless: a different kind of hell?
#379Earlier quoted context omitted.
MFA is required in the EU: https://en.wikipedia.org/wiki/Strong_customer_authentication
Really interesting, here in Mexico I think that's unheard of, what I have to use is a digital card with a dynamic 3 digit cvv that's generated on my app.
Re: Passwordless: a different kind of hell?
#380Earlier quoted context omitted.
1Password can do this for you, and I assume many other password managers as well. https://support.1password.com/one-time-passwords/
I use 1password but opt out of this feature. Just as described in the article masterpassword creates a single source of failure so I don't personally want to put more eggs in that basket.