Live data from Hacker News

Password Security: Why the horse battery staple is not correct

diogomonica.com

1–10 of 92 posts

Re: Password Security: Why the horse battery staple is not correct

#4
I liked this article and largely agree with what it has to say, but I have a question related to a bit at the end.

The article recommends using multifactor authentication everywhere, which sounds great for keeping things extra secure. Recently, though, I got a new phone and I'm thankful that I only had two services for which I was using multifactor authentication because otherwise I would have had to remember to set up even more than those two services on my new phone.

Is there any good solution to that problem?

Re: Password Security: Why the horse battery staple is not correct

#5
post #2

Good point and article. I wish there was a de facto standard password manager/data format (open source, free, works everywhere). As it stands, there are many good ones, and it's hard to choose one , even though any choice is better than no choice.

I've used both LastPass and 1Password and while they're not open source or free, I have enjoyed using them both. I currently use 1Password and find it to be a great experience.

Re: Password Security: Why the horse battery staple is not correct

#8
post #4

I liked this article and largely agree with what it has to say, but I have a question related to a bit at the end. The article recommends using multifactor authentication everywhere, which sounds great for keeping things extra secure. Recently, though, I got a new phone and I'm thankful that I only had two services for which I was using multifactor authentication because otherwise I would have had to remember to set…

I save the QR codes on an encrypted disk image which I keep in "a safe place". There is also Authy[0] which supports backups.

[0]: https://www.authy.com/users

Re: Password Security: Why the horse battery staple is not correct

#10
post #4

I liked this article and largely agree with what it has to say, but I have a question related to a bit at the end. The article recommends using multifactor authentication everywhere, which sounds great for keeping things extra secure. Recently, though, I got a new phone and I'm thankful that I only had two services for which I was using multifactor authentication because otherwise I would have had to remember to set…

Good point, it is a problem.

I'm aware of two options:

- either you spend the time manually trying to going to all places where you use multi factor auth and perform "transfer device" process, which is hard and painful the more services you have,

- or you save backups of the original source elsewhere, basically invalidating the security advantage multi factor offers you.

Post reply on HN