Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

351–360 of 816 posts

Re: Emailing a one-time code is worse than passwords

#351
post #126
post #103

Earlier quoted context omitted.

I don’t like passkeys. Before my process to login was: - open website - if not already logged in, log in to 1Password - autofill password - autofill TOTP Now: - open website - if logged in to 1Password the Use Passkey usually shows up - if not: - log in to 1Password - choose use passkey - this almost always does nothing - choose “use other method” - choose “password” - autofill that - now there is another dialog to c…

Passkeys work very smoothly with Safari and Apple Passwords. Apple Passwords now sufficiently good to replace 1Password for me and I’m slowly transitioning. I don’t mind subscription models per se but there was something about subscription for your own passwords that made me refuse to jump the fence when 1Password switched to that model. Would be a bit faffy if you’re a Chrome user.

I stick with 1Password, because I don’t want my password manager to be part of the barrier to using other platforms.

I also have a bunch of stuff in 1Password that doesn’t have a home in Apple Passwords, which would be a problem.

And yes, Chrome with Apple Passwords is annoying. At work I’m forced to use Chrome for some things, and I’ve been dabbling with Apple Passwords. Every time I launch the browser I have to put in a code to link the extension with Passwords. It’s very annoying.

Re: Emailing a one-time code is worse than passwords

#352
post #152

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

> The attack pattern is: There are lots of attack patterns. That is one. I am not certain I believe it is very likely, because (a) I think "sign-in partner" is obvious bullshit, and (b) I don't understand why I would never enter a code into the wrong website. I believe it can be possible, but... > Passkeys is the way to go. ... I’d rather granny needs to visit the bank to get access to her account again, than someone…

>(a) I think "sign-in partner" is obvious bullshit

Nearly every website tries to offer Google or Microsoft based sign in, "sign in partners" are commonplace.

Re: Emailing a one-time code is worse than passwords

#354

Earlier quoted context omitted.

> Passkeys is the way to go. Password manager support for passkeys is getting really good. I set up a passkey for github at some point, and apparently saved it in Chrome. When I try to "use passkey for auth" with github, I get a popup from Chrome asking me to enter my google password manager's pin. I don't know what that pin is. I have no way of resetting that pin - there's nothing about the pin in my google profile,…

Passkeys are the pinnacle of bad UX. It just works, until the user tries to switch devices, accounts or platforms. The slogan of passkeys should be something like "I don't have a password, it usually just works, but now I changed X and it doesn't work anymore" . Even worse is hardware-based 2FA built into smartphones (also FIDO), as you lose your phone in a lake and now you can't access anything anymore. The way to g…

I use protonpass and it’s great, carried across all my devices and browsers.

Re: Emailing a one-time code is worse than passwords

#355
post #335

Earlier quoted context omitted.

No, which is why there is the cross platform standard CXF which allows for cross platform sharing of passkeys. Apple has announced that support for this is shipping later this year with iOS 26. Google hasn't announced when they are shipping it yet.

Would’ve been nice if the basic UX would have been figured out before passkeys were shoved down everyone’s throats

It just wasn't an important consideration, unlike the attestation anti-feature.

Re: Emailing a one-time code is worse than passwords

#356

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

But you could replace #2 with "Enter your password from GOOD, as they are our sign-in partner". I'm not in favor of emailing 6 digit codes either, but your scenario presupposes that users will be willing to trust that two services have intermingled their auth, and in that case their password can be wrangled from them too.

[deleted]

Re: Emailing a one-time code is worse than passwords

#357
post #342
post #128

Earlier quoted context omitted.

There's a tension here between "user freedom" and a service wanting to make sure that credentials that it trusts to grant access to stuff aren't just being yolo'd around into textfiles on people's dropboxes. People forget that one of the purposes of authentication is to protect both the end user and the service operator.

Note the scare quotes around user freedom. Perhaps user freedom is a notorious fake issue, a bizarre misconception, or an exotic concept that nobody understands.

I don't know what "scare quotes" are. They're just regular quotation marks, because I'm quoting.

Re: Emailing a one-time code is worse than passwords

#358

Relatedly with respect to passkeys, it seems we have the following tradeoff (simplified): 1. authentication via password: accounts stolen by criminals and then inaccessible to the user. 2. authentication via passkey: accounts lost by users because passkeys have friction, to say the least, when devices are lost/stolen/transferred. It seems that big providers would much rather scenario 2.

Yeah probably because stolen accounts are more of a hassle for them than lost accounts.

Re: Emailing a one-time code is worse than passwords

#359

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

Mobile phone App/Passkey authentication is just a way to pass the responsibility down to users. Losing a phone today is not just losing the passkey, there are "login with QR-code" schemes too, which do not need a password at all. It is a bad trend to pass all security onto the physical phone.

Re: Emailing a one-time code is worse than passwords

#360
post #357
post #342

Earlier quoted context omitted.

Note the scare quotes around user freedom. Perhaps user freedom is a notorious fake issue, a bizarre misconception, or an exotic concept that nobody understands.

I don't know what "scare quotes" are. They're just regular quotation marks, because I'm quoting.

Sure, I stand corrected, you "don't know" what I'm talking about.
Post reply on HN