Emailing a one-time code is worse than passwords
421–430 of 816 posts
Re: Emailing a one-time code is worse than passwords
#422The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…
Re: Emailing a one-time code is worse than passwords
#423Earlier quoted context omitted.
The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortuna…
Your style of thinking is exactly why linux never became a leader in desktop os's. Why we're still dealing with the most ridiculous tech debt and complexity in OSS tooling to date. You're obsessed with fake problems that have no bearing on real people. When grandma does indeed loose all her money because some prick phished her password away, I would love to watch you explain how that's actually better than BigTech ta…
Re: Emailing a one-time code is worse than passwords
#424Earlier quoted context omitted.
I have added what I think they call login alias to my account. This blocks logins using the normal account username (which is my public email address), and only allows them via the alias (which is not public and just a random string). Not a single foreign login attempt since I enabled the alias. You can enable it on account.microsoft.com > Account Info > Sign-in preferences > Add email > Add Alias and make it primary…
Then, is the login alias sort of a password? In that, it is something you know.
Re: Emailing a one-time code is worse than passwords
#425Earlier quoted context omitted.
/s tag? Peope do read, if the email is short
They only read what they need to finish what they are currently trying to do, which in this case is the code they need to log in.
On what grounds you say people dont read? Any evidence?
Re: Emailing a one-time code is worse than passwords
#426sure, it being a 6 digit code which has potential for social engineering can be an issue like similar to if you get a "your login" yes/no prompt on a authentication app, but a bit less easy to social engineer but a in turn also suspect to bruteforce attacks (similar to how TOTP is suspect to it) through on the other hand - some stuff has so low need of security that it's fine (like configuration site for email news l…
Did you mean to post this comment at https://news.ycombinator.com/item?id=44819917 ?
Re: Emailing a one-time code is worse than passwords
#427I'm in the rental market right now, and Zillow not only has a log-in for the app, but to read messages in your inbox, you have to MFA again each time, and the time-out period is about an hour.
We're being annoyed to death.
This is madness.
Re: Emailing a one-time code is worse than passwords
#428Re: Emailing a one-time code is worse than passwords
#429Re: Emailing a one-time code is worse than passwords
#430Earlier quoted context omitted.
It works fine until you dare to have TWO accounts for the same website. Safari will just randomly pick one of them and always tray to log you in with that passkey every time you visit, and the interface for using a different one is really annoying.
Maybe im misremembering, but I feel like it gave me an option between two accounts recently? Let me see if I can get it again
The implementation in Chromium browsers (I use Arc, so I can't speak to Chrome itself) is basically a chunkier-looking 1Password.