Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

261–270 of 392 posts

Re: Passwordless: a different kind of hell?

#261

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

Dutch people still jokingly invite newbies in the country to pronounce the name of the town 'Scheveningen'; this is kind of hard for native English speakers and very difficult for native German speakers, so it was used as a filter by the Dutch resistance during WW2.

Re: Passwordless: a different kind of hell?

#262
We have all been using physical keys for our homes and cars our whole lives. Physical U2F keys for digital authentication are basically the same level of convenience and actually very very secure: no shared secrets, not copyable, not forgeable, not vulnerable to phishing, etc. I don’t know why we haven’t all jumped on this solution to digital authentication

Re: Passwordless: a different kind of hell?

#263
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

Anyone else feels that the double clicking of the side button doesn't feel ergonomic? It doesn't feel right to me when doing it. I end up holding it like a gun, and then double clicking it, as in the default pose of holding a phone, my thumb is unable to double click.

Re: Passwordless: a different kind of hell?

#264
post #3

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

I came to this realisation not too long ago as well. It's saddening to imagine how much better the world in general would be if it weren't for criminals. Generations before mine talk about their childhood as a wonderful time. Not having to lock their bikes up when going into a shop. Not having security cameras watching their every move. Not having barriers everywhere to prevent theft. My local supermarket introduced…

Bear in mind that the security/surveillance sector of the economy (including police) are heavily incentivized to exaggerate the risks of crime, as are politicians who want to appeal to a certain sort of voter. There's a lot of money to be made out of running a police state.

Re: Passwordless: a different kind of hell?

#265
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Why is your password manager only on your phone and not synced between your devices?

Re: Passwordless: a different kind of hell?

#266

Earlier quoted context omitted.

Apple makes this experience as seamless as I think it possibly can be. (As long as you use Safari...). All my passwords synced across all devices all the time, instantly available with faceID or or my fingerprint. Apply pay makes checking out of most online retailers as fast as using my fingerprint or double-clicking the side button on my phone. Passkeys generally starting to replace passwords on many major sites, ma…

Anyone else feels that the double clicking of the side button doesn't feel ergonomic? It doesn't feel right to me when doing it. I end up holding it like a gun, and then double clicking it, as in the default pose of holding a phone, my thumb is unable to double click.

Agree, it's somehow unwieldy... not sure what it is exactly.

Re: Passwordless: a different kind of hell?

#267
post #177
post #45

Earlier quoted context omitted.

This looks like a ridiculous strawman's argument. For example, there's a large difference between stealing food from a produce stand (which I would certainly do if the alternative was to starve) and "carjacking people." I agree with the OP - as a society, we should look more at aligning incentives rather than instilling morals. Another huge area this comes up is the war on drugs - if you're caught with drugs, we slap…

>if you're caught with drugs, we slap you with a felony that ensures you can't get a real job... pushing you right back to drugs. I could say the same thing for any sort of crime. If you're an accountant, and you get put in jail for embezzling, that conviction is going to prevent you from getting another job as an accountant. While there have been a few controversies about jobs that the law excludes felons from, in a…

What a weird comparison. Embezzling is abusing a position of trust to become a thief. Who was abused if someone privately consumed drugs?

Re: Passwordless: a different kind of hell?

#268

Earlier quoted context omitted.

You don’t have to give Apple your data. It uses information stored on device.

Seems like parsing semantics. "Pre-given them" - are you giving it directly to apple.com? No. You're putting in your hardware, true. And... somehow... it makes it to all your other apple devices.

[deleted]

Re: Passwordless: a different kind of hell?

#269

Earlier quoted context omitted.

You don’t have to give Apple your data. It uses information stored on device.

Seems like parsing semantics. "Pre-given them" - are you giving it directly to apple.com? No. You're putting in your hardware, true. And... somehow... it makes it to all your other apple devices.

> somehow... it makes it to all your other apple devices.

"Somehow" their information makes it around? No, you have to add them, yourself, on every device you use them from, individually.

Re: Passwordless: a different kind of hell?

#270
post #80

Earlier quoted context omitted.

Privacy[.]com replaced my PayPal usage pretty much completely. Virtual credit cards tied to individual merchants with limits.

And tied to a direct back account, requiring you to use cash and lose any CC benefits. I use Privacy for things I know I only want to charge once (e.g. $1 trials or things of that nature) but not being able to charge a CC with Privacy is a bit blocker most of the time.

Sure, but I don’t get rewards with PayPal, so it’s a non issue?

Or you are saying it’s not worth reducing your usage of PayPal unless you get rewards?

Post reply on HN