Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

171–180 of 392 posts

Re: Passwordless: a different kind of hell?

#171

Earlier quoted context omitted.

That whole process in the top level comment is much faster, in practice, on my phone. Everything auto-fills (unless a site manages to fuck up their forms). I don’t typically have to type or manually copy anything, including 2fa tokens. Wait for the notification to ping, “fill from message” option, done. I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single th…

How are you populating non-SMS 2FA codes automatically?

Apple hardware can auto-fill 2FA codes if the codes are set up in the Passwords tool on iOS/iPadOS/macOS, which are synchronized through iCloud.

Re: Passwordless: a different kind of hell?

#172

We are going way over the top with 2FA. Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.…

[deleted]

Re: Passwordless: a different kind of hell?

#173
post #125

Earlier quoted context omitted.

Github 2FA is made extra fun because they only offer a single mechanic of replacing it (that I know of), and that's using the recovery codes. So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow). When I bought a new iPhon…

TOTP backups from phones is a major issue, from what I can tell you simply can't do it.

It's the Google Authenticator app's fault. The most popular TOTP app probably, and for a long time, they were saying it's intentionally designed not to let you copy the codes. Now you can, but there are lots of pitfalls and vague documentation. I'm not convinced that TOTP is a user-friendly design to begin with, but it didn't have to be this bad.

I don't fw TOTP now. There are other apps, but I'm done. I'll only use it if the iPhone Keychain has built-in support some day.

Re: Passwordless: a different kind of hell?

#174

Earlier quoted context omitted.

We shouldn't have to work installing & maintaining an awkward flow with random software to make buying experience less miserable. This should be fixed by the seller in the first place, where it makes sense and can be fixed easily and reliably.

In general I agree, but KDE Connect is not random software and it's fucking awesome, especially if you are a KDE user, for a lot of reasons. The use-case described in the grandparent is just one of many handy things available via KDE Connect

I use GNOME: the gsconnect extension on my laptop, the kdeconnect app on my mobile devices. They can even share data and files between themselves without going through the laptop, ring another one when I lost it somewhere at home, control the media playing on another device or my laptop.

Re: Passwordless: a different kind of hell?

#175
post #17

Earlier quoted context omitted.

Apple pay when available is about as low friction as you can get. I know it isnt available to everyone but there should be some similar standard that is. Near seamless.

Only because you've standardized on their ecosystem and pre-given them all your data. This is not the future we were promised

You don’t have to give Apple your data. It uses information stored on device.

Re: Passwordless: a different kind of hell?

#176

Note that all uses of the password before the computer were not for personal security, but organizational security. If the enemy infiltrated without the use of the password, it could mean the downfall of an empire. Today we use passwords largely for personal security. Yet when companies choose what methods of authentication/authorization they offer, they don't care what the user wants. They pick methods that will mak…

The "standard" is to have someone else deal with it. Login with Auth0/Apple/Facebook/Google/GitHub/Microsoft/GitHub/Twitter/etc is that.

It's comical, some site only allowed auth via Twitter, and I signed up for Twitter via a burner Google account. I get redirected like 30 times logging in and asked about my favorite celebrities along the way.

Re: Passwordless: a different kind of hell?

#177
post #45

Earlier quoted context omitted.

If you were poor, you'd be carjacking people?

This looks like a ridiculous strawman's argument. For example, there's a large difference between stealing food from a produce stand (which I would certainly do if the alternative was to starve) and "carjacking people." I agree with the OP - as a society, we should look more at aligning incentives rather than instilling morals. Another huge area this comes up is the war on drugs - if you're caught with drugs, we slap…

>if you're caught with drugs, we slap you with a felony that ensures you can't get a real job... pushing you right back to drugs.

I could say the same thing for any sort of crime. If you're an accountant, and you get put in jail for embezzling, that conviction is going to prevent you from getting another job as an accountant.

While there have been a few controversies about jobs that the law excludes felons from, in a lot of cases there's nothing preventing you from hiring a felony drug criminal. If you personally are fine with drugs and you think that committing the crime doesn't make him a danger to your business, go ahead and hire him. If you won't, it isn't the conviction that's keeping him from being hired, it's the crime; the conviction just lets you know that he committed a crime.

Re: Passwordless: a different kind of hell?

#178

Earlier quoted context omitted.

> Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? Because your hobby-project can emerge to be the backbone of someone's multibillion dollar-business, or a small gear in a million other projects, and you will get targeted for a supply-chain-attack.

You are right. However this cost should really be imposed on the multi-billion-dollar business and not on the author of the hobby app.

How should that work? Nobody knows who is using which part from which repo. And it's not just about big business. There are all kind of small communities and little apps, extensions, etc. with some small communities. Most of them don't even make money, but are juicy targets for some small fast money.

Forcing everyone to raise their security and gain awareness about those things is a huge win for everyone, and only a little problem for the individual user. And it seems to be only a phase anyway, as most people & services are moving to more comfortable solutions over time.

Re: Passwordless: a different kind of hell?

#179
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

I've never had to authenticate with a bank for using a card? Is this common for you?

I'm in the US, and for some purchases I have to. There's like an iframe in which I have to log into my credit card account, and approve the transaction.

I'm not sure what triggers it.

Re: Passwordless: a different kind of hell?

#180
post #136

Earlier quoted context omitted.

In this case, how is eBay responsible for how PayPal and a bank handles things when they hand it off?

eBay owns PayPal https://www.cnet.com/tech/tech-industry/ebay-picks-up-paypal... - August 2002

No, eBay no longer owns PayPal.

https://techcrunch.com/2014/09/30/ebay-paypal-split/

Post reply on HN