Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

391–392 of 392 posts

Re: Passwordless: a different kind of hell?

#391

Earlier quoted context omitted.

Seems like parsing semantics. "Pre-given them" - are you giving it directly to apple.com? No. You're putting in your hardware, true. And... somehow... it makes it to all your other apple devices.

> somehow... it makes it to all your other apple devices. "Somehow" their information makes it around? No, you have to add them, yourself, on every device you use them from, individually.

No, I don't. If I put info in the phone, it's available on safari on macOS. I'm fairly certain I didn't enter it multiple times.

Re: Passwordless: a different kind of hell?

#392
post #113

SMS-based 2FA is still vulnerable to phishing, but U2F is not. This has been solved for a while now, but I guess it's still a hassle for most folks to use them. I got my whole family Yubikeys a while back, and it seems to be going pretty well.

How do you backup access? The one thing that's stopped me from pulling the trigger on U2F is if that device is lost, stolen, or broken then I'm hosed, right? With standard 2FA, I have backup devices and codes that I can start restart from scratch if my phone is ever lost/stolen/broken.

Write down your backup codes. Register a second key if possible. Google accounts are set up to prompt phones, too. In some cases we still have SMS 2FA enabled.
Post reply on HN