Passwordless: a different kind of hell?
11–20 of 392 posts
Re: Passwordless: a different kind of hell?
#12Biometrics seem worse-is-better: you now have some unique identifier for me, which is totally swell until the inevitable DB breach. Which breech will likely be due to an Admin whoopsie of some sort. Because the people remain the weakest link.
Re: Passwordless: a different kind of hell?
#13Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.
And in more serious services, like banking... since there is no such thing about 100% security (and in particular 2FA is far from it, e.g. if your phone is stolen with the banking app open, you're screwed), actually the most important thing is that the bank responds and can refund the money if fraud is committed, which it inevitably will for some percentage of unlucky customers. I view 2FA as a way to pass responsability to the customer ("we have very secure systems, so if someone transferred $X out of your account it's surely your fault"). Personally, I feel safer with less security and the bank worrying about fraud than the other way around, so I don't think they're protecting me when they implement this kind of stuff.
Re: Passwordless: a different kind of hell?
#14We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…
Re: Passwordless: a different kind of hell?
#15Biometrics seem worse-is-better: you now have some unique identifier for me, which is totally swell until the inevitable DB breach. Which breech will likely be due to an Admin whoopsie of some sort. Because the people remain the weakest link.
Could you elaborate on your concern? My understanding of how most biometric auth works is that it functions a lot like passwords in that your features get translated into a non-reversible hash that should be meaningless to any other biometric auth system.
Re: Passwordless: a different kind of hell?
#16Trusting 743 “randos on the internet” to safeguard “my” data, and give me access to use it.
Insanity.
Agent-Centric systems where I retain signing keys to authorize access to (and transactions using my) data are the way forward.
A Key Fob (like you have for your car) is not onerous, and methods for recovery using trusted community members is practical.
Holochain (and the Holo project) are good examples of working implementations.
Re: Passwordless: a different kind of hell?
#17I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…
Re: Passwordless: a different kind of hell?
#18I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…
Re: Passwordless: a different kind of hell?
#19The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.
Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…
People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for.
There are many people out there having a really hard time who would never even think about stealing because they were raised with a functioning moral compass.