Live data from Hacker News

Password reuse is rampant: nearly half of observed user logins are compromised

blog.cloudflare.com

11–20 of 51 posts

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#11
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

Just use a KeepassXC and you are 99% there. Add some Browser extension that synchs with it and only use randomly generated passwords.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#15

Maybe if we weren't letting a third party sign arbitrary certificates for arbitrary domains they wouldn't be reading our passwords. People don't realise CloudFlare is a MitM-as-a-Service.

What do you mean? Is cloudflare causing 3rd parties to read our passwords?

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#17
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

Biometrics are really not fine. They're somehow supposed to be some permanent marker of who you are, but that's really not how it works in the real world. You physically change.

I've broken any biometrics recognising me in a dozen different ways, this year alone. Cut open my finger, changing my fingerprint. Head surgery for melanoma gave me a scar so facial recognition doesn't work anymore, blood vessel burst in my eye, so iris scan changed. And so on.

They're fine for a convenience, but that's it. They're nothing more than a pin, and you will have to fall back to password or authenticator or something else, sooner or later.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#19
post #5
post #3

[flagged]

"As part of our Application Security offering, we offer a free feature that checks if a password has been leaked in a known data breach of another service or application on the Internet. When we perform these checks, Cloudflare does not access or store plaintext end user passwords." https://developers.cloudflare.com/waf/detections/leaked-cred...

A lot of software and services do this. Firefox, bitwarden. (I believe you have to opt in and or click a button each time) Just the other day bitwarden was helpfully telling me my bank password was compromised 8000 so times. It's a 4 digit pin by the way of which huge chunka are not allowed in the name of more security. 1900s and 2000s too much like a birth year, no way. No 2 same numbers consecutively. Nothing starting with zero. Etc etc.

Re: Password reuse is rampant: nearly half of observed user logins are compromised

#20
post #17
post #2

Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common. For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.

Biometrics are really not fine. They're somehow supposed to be some permanent marker of who you are, but that's really not how it works in the real world. You physically change. I've broken any biometrics recognising me in a dozen different ways, this year alone. Cut open my finger, changing my fingerprint. Head surgery for melanoma gave me a scar so facial recognition doesn't work anymore, blood vessel burst in my e…

Also, even if they work as desired, if they're ever compromised [1], you're permanently unable to use that form of authentication, or permanently vulnerable to services that use and/or require it.

[1] https://en.wikipedia.org/wiki/Biometrics#Data_security

Post reply on HN