Live data from Hacker News

The "email is authentication" pattern

rubenerd.com

371–380 of 474 posts

Re: The "email is authentication" pattern

#371

Earlier quoted context omitted.

I might be mistaken, but are not several "traditional" banks offering crypto wallets for customers? Is there a realistic chance this kind of bank is going to steal their customers' crypto and going (at least, next to criminal investigations) bankrupt over it?

Sure, they could. Would that be any different from how a bank could steal funds from a traditional deposit account? By making a bank the custodian of your crypto wallet, you're placing your trust in them and should have similar legal recourse you would have had with a fiat deposit.

I am not sure if you are objecting. Definitely you need to trust your bank if you are going store your crypto with them. I just do not see any large traditional bank stealing their customers' crypto and hoping to get away with it.

As far as I know all the cases of stolen crypto have been newly founded companies with their only business being your crypto. That is quite unlike the other kind of bank.

Re: The "email is authentication" pattern

#372

Earlier quoted context omitted.

A $1 note being a macro scale physical object enjoys a variety of benefits such as object permanence which provide a baseline level of recoverability. Whereas a wallet key l, being a number, enjoys no such protections. Of course you may choose to encode your wallet key on paper, metal, or stone granting it properties not unlike a note. However you have now compromised the security of your wallet as well it becomes no…

You can encode your bitcoin in wallets of predetermined size, spreading your risk. But you’re reinventing money with extra steps.

> But you’re reinventing money with extra steps.

But you gain some desirable properties over traditional money.

Without crypto, you don't have frictionless and permissionless transfers of arbitrary value across international borders.

Re: The "email is authentication" pattern

#373
post #243

Earlier quoted context omitted.

Physical money is physically recoverable after lost

For the system yes, a dropped coin eventually reenters the market and a burned bill can be reprinted again. Can't say the same about a crypto wallet. For an individual though, in both cases, a lost wallet is a lost wallet. While an interesting difference to study, the average person is not going to care about the former case. They just don't want to keep their life savings in an asset as easy to loose as their pocket…

If you drop your wallet in a bar, there's a chance you can recover it by returning to the bar and searching for it, by the bartender or a patron returning it to you based on the address or a number in your wallet, etc. Physical money really is not the same, even for the individual.

Re: The "email is authentication" pattern

#374
post #366

Earlier quoted context omitted.

I don't. And frankly I don't think a safe is a good place to store secrets. It is too conspicuous.

These safes are certified for all kinds of sensitive (GSA recommends them for Classified use from what I have read) use and they are safe. Ideally, you connect Vault to a HSM if you need that kind of security that’s being described. HSMs are electronic safes

> These safes are certified for classified use and they are safe.

The website says "10 minutes against forced entry". That's not safe.

No safe is safe against a state level actor. No safe is safe against "hit you with a crowbar until you open the safe".

Whatever secrets you have, it's better to hide them than to put them in such a conspicuous place. The only reason one should use a safe is as a plausible decoy...

Re: The "email is authentication" pattern

#375
post #120

Earlier quoted context omitted.

> If the answer is "they just don't get access anymore" or "a panel of their peers attests to them", your fantasy authentication system also needs a fantasy species of sentient beings to serve as users, because it won't work for humans. This has been my single biggest argument against blockchain/cryptocurrency stuff for years: the "lose your key, lose your wallet" thing is fundamentally incompatible with real users.…

If you accidentally burn cash you cannot recover it. The paper in your hand isn't replicated in another place. Humans have been unable to recover from mistakes since day zero

> If you accidentally burn cash you cannot recover it. The paper in your hand isn't replicated in another place.

Which is (one reason) why most people use a bank account and don't hide their money in big bundle of cash under their pillow?

Re: The "email is authentication" pattern

#376
post #174

Earlier quoted context omitted.

No, thank you. I don't want anybody with a fake ID of me to be able to take control of my email. I want to use my password, I want it strongly encrypted at rest, and I want to be able to reset it remotely any time of day, without waiting for the USPS office to open.

Is a fake ID going to fly at the post office, where they can scan them? Also, I was imagining they'd want more than just an ID. edit: Also also, they have to go into a physical post office and be observed trying to steal your account. Given how it's quite possible to steal accounts via social engineering, this seems like an improvement in security, not a reduction.

I don't want a government entity, or really any entity I'm not paying directly for their services, to be the gatekeeper between me and my accounts.

The social engineering attack surface of my account currently consists of a handful of support contacts at my ISP, who have been trained to deal with computer security. If you allow any USPS employee to access your account, you've suddenly increased the potential attack surface by several orders of magnitude.

Re: The "email is authentication" pattern

#377
post #357
post #327

Earlier quoted context omitted.

Apple is the worst about this. The only option is that they send a message to an Apple device. I only have an iPad and not an iPhone or Macbook, so I often simply cannot log into my Apple account because they refuse to do anything else besides send it to an Apple device.

Not true, you can use FIDO2 keys. You can even use SMS (but you shouldn't).

Yes, it is true. There are indeed cases where you are not presented with SMS options.

And I'm not going to purchase and carry around a hardware key just for the privilege of periodically logging into my Apple accounts.

Maybe Apple shouldn't force you to own an Apple device to login to your accounts? They've been sued about this before and lost. If Microsoft did this, people would lose their minds.

Re: The "email is authentication" pattern

#378

Their motivation is immediately clear to me. If you use "I forgot my password" you don't have to remember a password. And it doesn't even make your account less secure, since that pathway was going to be available to attackers regardless. I've seen websites that make that their default flow, arguing (implicitly) that having passwords at all is pointless when you can just email someone a login button, skipping a step.…

> it's not "2FA" if the second factor is the only one I need

It will be 2FA again if you protect your email with 2FA

Re: The "email is authentication" pattern

#379
post #374

Earlier quoted context omitted.

These safes are certified for all kinds of sensitive (GSA recommends them for Classified use from what I have read) use and they are safe. Ideally, you connect Vault to a HSM if you need that kind of security that’s being described. HSMs are electronic safes

> These safes are certified for classified use and they are safe. The website says "10 minutes against forced entry". That's not safe. No safe is safe against a state level actor. No safe is safe against "hit you with a crowbar until you open the safe". Whatever secrets you have, it's better to hide them than to put them in such a conspicuous place. The only reason one should use a safe is as a plausible decoy...

This isn’t the safe to rule all safes. You have other mitigating factors like access control.

If you have state level actors physically breaking into your facilities then we might be at war

Re: The "email is authentication" pattern

#380

Earlier quoted context omitted.

You can encode your bitcoin in wallets of predetermined size, spreading your risk. But you’re reinventing money with extra steps.

> But you’re reinventing money with extra steps. But you gain some desirable properties over traditional money. Without crypto, you don't have frictionless and permissionless transfers of arbitrary value across international borders.

There's no fundamental property of the monetary system that prevents transfers of arbitrary value across international borders. There's just a large number of financial regulators, border guards, etc. who will throw you in jail if you carry a big block of gold across the border or accept a large wire transfer without filling out the necessary forms. In many countries, the laws governing those forms don't yet apply to cryptocurrencies, but I'm skeptical it will remain that way forever.
Post reply on HN