Live data from Hacker News

Password reuse is rampant: nearly half of observed user logins are compromised

blog.cloudflare.com

1–10 of 51 posts

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#2
Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common.

For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#5
post #3

[flagged]

"As part of our Application Security offering, we offer a free feature that checks if a password has been leaked in a known data breach of another service or application on the Internet. When we perform these checks, Cloudflare does not access or store plaintext end user passwords."

https://developers.cloudflare.com/waf/detections/leaked-cred...

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#6
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

I want to be able to tie digital credentials to my identity so if they are compromised or I loose access I can recover them by providing my national ID documents. Similar how I do with my bank app, I go to the bank, show my ID, sign some forms and reset all the creds. I don't have to fear loosing access. On the other hand if I loose my google account I'm screwed, all my other services depend on either my email address or google 2fa keys to prove my identity.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#8
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

> a "super-secure" password for if something happens that can only be used once

With 99.99% chance you forget it before you ever get to enter it because humans forget things they never use :)

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#9
post #8
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

> a "super-secure" password for if something happens that can only be used once With 99.99% chance you forget it before you ever get to enter it because humans forget things they never use :)

You can store it in paper with your other important documents. It's not unstealable but if someone nicks your document folders you're spending two weeks redoing/reissuing everything anyway.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#10
post #6
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

I want to be able to tie digital credentials to my identity so if they are compromised or I loose access I can recover them by providing my national ID documents. Similar how I do with my bank app, I go to the bank, show my ID, sign some forms and reset all the creds. I don't have to fear loosing access. On the other hand if I loose my google account I'm screwed, all my other services depend on either my email addres…

I fear that mixing government IDs to commonly used digital credentials could invite lots of privacy violations from businesses and governments.

It'd be much easier for porn & social media ID laws to be enforced. Which could be abused by adtech and law enforcement.

Post reply on HN