Live data from Hacker News

Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

foundation.mozilla.org

21–30 of 75 posts

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#21

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

I don't understand what they mean by strong passwords.

From the methodology:

> If the product uses passwords or other means of security for remote authentication, it must require that strong passwords are used, including having password strength requirements.

What are 'strength requirements'? Is minimum-length-of-X a strength requirement? Apparently not, since Abide failed for the following:

> Strong password: No. Allowed us to register with '11111111'. They require 8 characters minimum, but do not check if a password is strong.

----

I don't believe in the meme of l337speak pa55W0rd$. I think sufficiently long pass phrases are fine.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#22
post #4
post #2

[flagged]

My reaction, too. OTOH, the article is pretty obviously aimed at an audience which might really benefit from some more "...and don't stick your finger in a light socket, either!"-level warnings.

We all benefit from those warnings. Who isn't taught to not stick their fingers in light sockets?

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#23
post #10

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

There are substantial incentives for practically everyone to adopt strong passwords, including yourself, even if it's just a temporary account. The platform actually desires you to possess a robust password, given that hijacked accounts contribute to spam so heavily. Many people often use the same "basic passwords" on multiple websites. If one of your temporary accounts gets hijacked all your other "temporary" (in qu…

> Essentially, there are hardly any valid grounds for any platform to permit the utilization of frail passwords, especially considering how effortless it is to create distinct passwords using a password manager nowadays.

One was just given: Users don't really care to create an account to begin with, so they provide throwaway email accounts and low security passwords. If the apps required longer, safer passwords, then they risk losing signups.

If I get a message complaining about my password being to weak, from a service I might not care that much about, then there's an increased risk that I opt to not create an account.

Apple solution is actually pretty good, it allows me to quickly create an account to try out an app or service. If I don't like it, meeh, they only have the Apple login info and nothing else.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#24
post #10

Earlier quoted context omitted.

There are substantial incentives for practically everyone to adopt strong passwords, including yourself, even if it's just a temporary account. The platform actually desires you to possess a robust password, given that hijacked accounts contribute to spam so heavily. Many people often use the same "basic passwords" on multiple websites. If one of your temporary accounts gets hijacked all your other "temporary" (in qu…

> Essentially, there are hardly any valid grounds for any platform to permit the utilization of frail passwords, especially considering how effortless it is to create distinct passwords using a password manager nowadays. One was just given: Users don't really care to create an account to begin with, so they provide throwaway email accounts and low security passwords. If the apps required longer, safer passwords, then…

It's clear that platforms don't view it as a major obstacle to registrations. Or, at least, not a hassle that weighs significantly against the issue of unauthorized access to accounts and, to put it bluntly, articles of this nature that tarnish their reputation.

Considering the ongoing trend towards the use of robust passwords rather than their abandonment, we can infer that either the impact on meaningful engagement hasn't been substantial or the decrease in signups is deemed overwhelmingly worthwhile in order to combat spam and other unfavorable aspects.

So, I stand by what I said.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#25

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

Passwords are not about hiding data. Passwords are legally the only thing that can't be forced out of you, to make you login into a computer system against your interests. Passwords are the core foundation of keeping your internet life separate from your personal/private life. Biometric and hardware authentication make both your real life name/address/life history and your computer ID the same thing. I didn't sign up…

> Passwords are legally the only thing that can't be forced out of you, to make you login into a computer system against your interests.

Not in the UK, since RIPA.

https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...

It's been used:

http://news.bbc.co.uk/1/hi/technology/7102180.stm

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#26
Nice to see that the app I use, Finch, is rated fairly well.

I'm going to assume sharing an invite code would go badly, but if you want mine so you get a mini pet in the app, please email me at the address in my profile. The benefit I get is not monetary: if I get a few signups I get a mini pet myself.

Finch is one of the few self help apps that really seems to help me. I was slipping further into deep depression but Finch has helped me to have a few good days, and I've showered and changed my clothes every day for 2 weeks. I recommend it!

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#27

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

The list is about privacy and security. If you don’t think your prayers are private or need security, then don’t worry about the list I guess.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#28

Earlier quoted context omitted.

Passwords are not about hiding data. Passwords are legally the only thing that can't be forced out of you, to make you login into a computer system against your interests. Passwords are the core foundation of keeping your internet life separate from your personal/private life. Biometric and hardware authentication make both your real life name/address/life history and your computer ID the same thing. I didn't sign up…

> Passwords are legally the only thing that can't be forced out of you, to make you login into a computer system against your interests. Not in the UK, since RIPA. https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po... It's been used: http://news.bbc.co.uk/1/hi/technology/7102180.stm

Guess my comment is surplus-to-requirements. Waves of 'sadge' aside..

Non-conformists are necessary to keep society progressing. The computing revolution is becoming oppressive. I guess the future rests with Men who have the willpower to keep valuable ideas out of the system long enough to for them to bear fruit.

Isaac Newton studied in private for 15yrs.. He also privately denied the Trinity and refused to take Holy Orders from the CofE. It's very questionable if that is at all possible to do again under constant 'supervision', when a fundamental difference between authority and truth happens again.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#29

>Mozilla’s Minimum Security Standards, like requiring strong passwords What if I don't want a strong password? What if I have 0 care for my account because I never wanted an account to being with but was strong armed into giving away my email, phone number, and now need a unique password because I'm worried someone is going to see that I 'prayed' 100 times. I loved that reddit didn't need an email, and I could use a…

Why do I need a password at all for 99.99% of apps or websites?

If I lose a password, what do I almost always have to do?

1. Email account recovery link.

2. Input auth code sent from text message or authenticator app. [Optional.]

3. Make new random password I'm going to forget or lose.

Why bother with this? If email is the reset mechanism why does the industry care so much about getting passwords from users?

1. Email sign-in link.

2. Input auth code. [Optional]

Everything other part of this whole chain gets simpler. No more password strength checking code. No multiple auth paths. No issues with anything. Just a single email with at most two links, one for browser sign in, one for app sign in.

If you really, really, really need to you can add one or two QR codes so these hypothetical people that don't have email on their phone can sign into the app.

Re: Top Mental Health and Prayer Apps Fail at Privacy, Security (2022)

#30

Earlier quoted context omitted.

I think creating a strong password and offering it once is better or am I overlooking something?

Offering it once? Offering what?

The password, at account creation. Here is your password: ……

I have seen it being used for cert keys.

Post reply on HN