Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

441–450 of 816 posts

Re: Emailing a one-time code is worse than passwords

#441
post #192

Earlier quoted context omitted.

that says more about 1Password than about passkeys. With 1Password I often get "does nothing" when trying to autofill good old regular passwords

1. I don't get that with 1Password 2. If you get this often, why do you use 1Password, honest question.

Vendor lock-in and lack of alternatives.

1Password used to work decently well before 2020. Now I have ~ 2k items in 1Password, distributed among two accounts (work and personal). Additionally, my spouse and I have a shared 1Password vault via the Family plan.

There’s no way I’m going to migrate 2k items and two dozen devices to another vendor. If there were one that met my requirements to begin with.

Re: Emailing a one-time code is worse than passwords

#442
post #231

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

> Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. I am waiting for the era when using passkeys is not depending from…

I use them without being dependent on big tech.

Re: Emailing a one-time code is worse than passwords

#443

Earlier quoted context omitted.

Maybe im misremembering, but I feel like it gave me an option between two accounts recently? Let me see if I can get it again

Apple handles it cleanly in Safari (you get a list of the accounts you're registered with on macOS, and iOS gives you the two most-recently-used accounts for that website with a button to reveal more). The implementation in Chromium browsers (I use Arc, so I can't speak to Chrome itself) is basically a chunkier-looking 1Password.

Ahhh I see. Typical Apple, honestly

Re: Emailing a one-time code is worse than passwords

#444

Earlier quoted context omitted.

For the record, if you're in the EU you can make a GDPR request to their Data Protection Officer - since it's your data what's being kept away from you, you have the right to at least a backup. It can take months and it only guarantees a backup, not full access, but it's better than nothing.

How would you prove to their data protection officer that you are the owner of that Gmail account?

In theory: they can ask for ID, sworn affidavit, or whatever other means their local laws determine to be valid. At the end of the day, proving that someone owns something is not a new problem. I've also seen "here's some evidence that I know what the contents of the account are, my legal name matches the account and my legal address matches some emails there".

In practice: in my case, anecdotally, they just did it. For some reason owning the backup email account was not enough for the automated workflow to unlock my account, but sending a letter threatening to sue under the GDPR somehow changed their minds.

Re: Emailing a one-time code is worse than passwords

#445
post #177
post #103

Earlier quoted context omitted.

I don’t like passkeys. Before my process to login was: - open website - if not already logged in, log in to 1Password - autofill password - autofill TOTP Now: - open website - if logged in to 1Password the Use Passkey usually shows up - if not: - log in to 1Password - choose use passkey - this almost always does nothing - choose “use other method” - choose “password” - autofill that - now there is another dialog to c…

That just sounds like you made a poor choice of password manager that doesn't put a priority on good ux...

1Password used to be decent until they enshittified about five years ago, decided to rewrite their app from scratch in Electron, replaced their support staff with non-technical staff who are unable to write any meaningful response to critical bug reports, and hired developers who allowed the app to degrade beyond recognition.

Re: Emailing a one-time code is worse than passwords

#446

Earlier quoted context omitted.

Yeah, that's why bcrypt is broken and shouldn't be used today. It had a good run, but nowadays we have better options like scrypt or argon2.

It's not broken. It's just potentially less helpful when it comes to protecting poor guessable passwords. bcrypt isn't the problem, weak password policies/habits are. Like bcrypt, argon2 is just a bandaid, though a tiny bit thicker. It won't save you from absurdly short passwords or silly "correct horse battery staple" advice, and it's no better than bcrypt at protecting proper unguessable passwords. Also, only devel…

Bcrypt alone is unfit for purpose. Argon2 does not need its input to be predigested.

It's easy for somebody who knows this to fix bcrypt, but silently truncating the input was an unforced error. The fact that it looks like and was often sold as the right tool for the job but isn't has led to real-world vulnerabilities.

It's a classic example of crypto people not anticipating how things actually get used.

(Otherwise, though, I agree)

Re: Emailing a one-time code is worse than passwords

#447
post #231

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

> Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. I am waiting for the era when using passkeys is not depending from…

We're in that era. BitWarden supports them natively, and you can even self-host.

Re: Emailing a one-time code is worse than passwords

#448

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

>"I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money."

More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. I live in a third world country and even 2FA simply isn't viable for me due to how frequent phone robberies are. I've had to do the process once and it was a nightmare, whereas with passwords I can just log into Bitwarden wherever and I'm golden

Re: Emailing a one-time code is worse than passwords

#449
post #415

Earlier quoted context omitted.

Your style of thinking is exactly why linux never became a leader in desktop os's. Why we're still dealing with the most ridiculous tech debt and complexity in OSS tooling to date. You're obsessed with fake problems that have no bearing on real people. When grandma does indeed loose all her money because some prick phished her password away, I would love to watch you explain how that's actually better than BigTech ta…

You're the one dismissing real problems like "lose all passkeys when you lose your phone".

That doesn’t happen when you use Apple’s passwords ecosystem or 1Password. The backing databases are synchronized between devices.

Re: Emailing a one-time code is worse than passwords

#450

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

Please log into BAD.com - we're a login provider to GOOD.com with a higher security level, from now on use BAD.com to log into GOOD.com Why would I put a secret code from GOOD.com into BAD.com? That's the core of the problem. If you put a code you get from GOOD.com into BAD.com, it's like you put a password from GOOD.com into BAD.com - don't do that.

> If you put a code you get from GOOD.com into BAD.com, it's like you put a password from GOOD.com into BAD.com - don't do that.

A password manager will protect me from doing the latter. There’s no way it can protect me from doing the former.

Any human can be tricked, no matter how smart they are. A bad actor just has to wait for the right moment. No amount of “don’t do that” can change that fact.

Post reply on HN