Live data from Hacker News

Passwordless: a different kind of hell?

jcarlosroldan.com

51–60 of 392 posts

Re: Passwordless: a different kind of hell?

#51
post #19

Earlier quoted context omitted.

Nah, thieves are scum. People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for. There are many people out there having a really hard time who would never even think about stealing because they were raised with…

This is why we can't have nice things.

[dead]

Re: Passwordless: a different kind of hell?

#52
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Sounds like you've got some unusual configuration options turned on or something.

The most glaring odd thing here is that you apparently don't have your password vault available on the same machine you're shopping from, which seems odd to me. Even so, if I went that route it'd still be easy b/c with the Apple ecosystem, the clipboard is shared between devices. One can copy a password from the phone and paste it on the Mac.

The tl;dr here is that I really don't understand why you had to retype your password. I never type my strong passwords. Why would you put yourself in a position where that's required?

Finally, when I pay via Paypal using my Amex, I never have to re-auth to Amex. It just flows through. So it sounds like that's something you've chosen to set up, not something inherent to the process.

Re: Passwordless: a different kind of hell?

#53
post #19
post #5

Earlier quoted context omitted.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

Nah, thieves are scum. People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for. There are many people out there having a really hard time who would never even think about stealing because they were raised with…

Both can be true: thieves are scum and modern society exacerbates the problem.

Sure, we should punish crime but never solving the root problem and taking a "hardline" approach towards the symptoms feels good. But, it puts us in a perpetual state of law enforcement and anxiety about crime.

Re: Passwordless: a different kind of hell?

#54
post #5

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

I know the GP used "thieves" as a comparison, but I think it took the conversation here a different direction than intended.

You can justify some thievery due to social problems - stealing for food is one thing.

But if you eliminate "fairytale concepts" like "bad actors", how do you explain the people constantly attacking managed services and trying to gain access to other people's accounts? These surely aren't the guy on the street looking for their next meal.

Re: Passwordless: a different kind of hell?

#55
post #5

Earlier quoted context omitted.

Thieves and other "bad actors" are often a consequence of deeper underlying problems. People don't tend to steal that much when they are economically comfortable. OTOH with no legal resort to get sustinence, you're guaranteed to get people to resort to illegal means. I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers…

If you were poor, you'd be carjacking people?

Quite possibly, especially if I'd be born into poverty. I gather you are quite sure you wouldn't?

Re: Passwordless: a different kind of hell?

#56

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

See also: the Parsley Massacre in the Dominican Republic, which preyed on Haitians' inability to pronounce the word "perejil" as a native Spanish speaker would:

> The Haitian languages, French and Haitian Creole, pronounce the r as a uvular approximant or a voiced velar fricative, respectively so their speakers can have difficulty pronouncing the alveolar tap or the alveolar trill of Spanish, the language of the Dominican Republic. Also, only Spanish but not French or Haitian Creole pronounces the j as the voiceless velar fricative. If they could pronounce it the Spanish way the soldiers considered them Dominican and let them live, but if they pronounced it the French or Creole way they considered them Haitian and murdered them.

https://en.wikipedia.org/wiki/Parsley_massacre

Re: Passwordless: a different kind of hell?

#57
post #7

I recently ordered something on ebay. Nothing expensive, just a £60 item, and delivered to an address I've ordered many things to in the past. First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols. Then ebay decided they wanted to sen…

Why would you submit yourself to using PayPal when you don't have to? Serious question.

PayPal is my first choice and if I go to check out on your store and you don't have PayPal as an option, the chances I abandon my cart if I don't have my wallet just went up exponentially. I use it as a buffer between me and the provider. Everything goes through a credit card so I still get the points/miles I would get entering the card directly. Except now they don't have a credit card token they can keep charging forever. They have a PayPal token that I can log into PayPal and immediately revoke, asynchronously, without involving the merchant or my credit card at all.

I don't need to worry about my details still being with that merchant. I don't have to worry about the merchant's convolution and likely-illegal cancellation process. The only negative I can think of is that any dispute has to go through PayPal, and while I've never done it I would bet money they are going to be skewed more in the merchant's favor than the credit card company. But that being said I have had fully legitimate chargebacks (as in not "I want a refund and they said no" but "this is a fraudulent charge I never agreed to") get denied and reversed by Discover so that's not a 100% certainty either.

I never receive money through PayPal so while I've read all the same horror stories everyone else has, that doesn't seem likely to affect me. My biggest gripe is the full-screen advertisement for whatever service they're pushing every time you log in on the website.

Re: Passwordless: a different kind of hell?

#58
post #38

The reason this happens is because of bad actors. This is why we can’t have nice things. Walk around and pay attention next time and you will notice all the little things that are shitty because of bad actors like thieves.

This happens because people won’t use a password manager and insist that “monkey123” is their super-secret unguessable password. The solution is to force them to use some kind of credential store (SMS 2FA, passkeys), because they can’t be entrusted to just hit the “generate secure password & save” prompt in the browser.

2FA is more than defending against bad passwords but also compromised passwords (e.g. you accidentally share it in a public forum) and phishing attacks. It's very unlikely a bad actor has access to both factors.

Re: Passwordless: a different kind of hell?

#59

> Gileadite soldiers used the word "shibboleth" to detect their enemies, the Ephraimites. The Ephraimites spoke in a different dialect so that they would say "sibboleth" instead. Experience : you just had to say a word. Security : there's a single word to authenticate multiple users and it can be cracked by learning how to spell it. Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording…

Case in point - Hebrew lost “Ghayin” way back in history so the Hebrew for Gaza is “’Aza” (with ‘Ayin)

Re: Passwordless: a different kind of hell?

#60

Earlier quoted context omitted.

It's quicker than entering your credit card details and address again and again.

If you use a password manager (which they say they do) it's much quicker to just save that info and automatically populate it. Doubly so considering the MFA hell they went through.

Too many sites have broken forms. Sure, you can have the card autofilled but maybe it doesn't trigger the autofill for the address or maybe that wasn't even loaded yet. Maybe you can just click there and have it auto-fill but they can be so broken it doesn't autofill completely or fills wrong. Some sites are smart enough to have a checkbox for "shipping address is the same as billing" and others aren't.

When you use a 3rd party payment provider like PayPal it does a really good job of forcing all of this to be automatic compared to things trying to autofill custom forms just because it's integrated by the site instead of the user. MFA hell is starting to erode that actually being easier though and now there is more and more often no simple approach left.

Post reply on HN