Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

571–580 of 816 posts

Re: Emailing a one-time code is worse than passwords

#571

Earlier quoted context omitted.

Yes, we've seen you repeat that we have to read it again. I reread this morning before the post, but really just found more things supporting my position. > To be very honest here, you risk having KeePassXC blocked by relying parties (similar to #10406). From the linked https://github.com/keepassxreboot/keepassxc/issues/10406 > | no signed stamp of approval from on high > see above. Once certification and attestation…

So you’re just not gonna respond to any of the points explaining your straw man. Yeah you should read it again, and read my explanation again and let me know if you have any questions or responses. Dont douse yourself in gasoline and you won’t have to worry about being on fire. (You have every right do douse yourself in gasoline. No one is taking that way from you. Just say away from everyone else)

Maybe you can let us know what definition of "strawman" you are using in this context?

KeePassXC is at risk of being blocked for making it easy to back up the passkeys. I don't see where that's been disproven or explained, other than saying "well attestation isn't enforced yet" -- that is, the metaphorical gasoline (provider AAGUIDs) hasn't yet been ignited (blocking of provider AAGUIDs)

> The entire issue is about doing the minimum possible of not exporting it in plaintext. Nothing is stopping you from decrypting it and posting it on your Twitter if you so wish. Just don't have the password manager encourage bad practices.

I don't disagree with this in principle, but it does warn you and realistically, what is the threat model here? It seems more like a defense-in-depth measure rather than a 5-alarm fire worthy of threatening to blacklist a provider. Maybe focus energy instead on this? (3+ year workstream now I guess?)

>> Sounds like the minimal export standard for portability needs to be defined as well.

> This is all part of the 2+ year workstream.

--

The more I get exposed to this topic, the less I'm convinced it was designed around people in the real world, e.g. https://news.ycombinator.com/item?id=44821601. Sure is convenient that it's so so easy to get locked into a particular provider, though!

Re: Emailing a one-time code is worse than passwords

#572

Earlier quoted context omitted.

I have added what I think they call login alias to my account. This blocks logins using the normal account username (which is my public email address), and only allows them via the alias (which is not public and just a random string). Not a single foreign login attempt since I enabled the alias. You can enable it on account.microsoft.com > Account Info > Sign-in preferences > Add email > Add Alias and make it primary…

I hadn't thought of this use case for aliases. I had to make my Outlook email primary again on my Microsoft account, unfortunately, because of how I use OneDrive. I send people share invitations and there are scenarios (or at least there were the last time I checked) where sending invitations from the primary account email is the only way to deliver the invite. If your external email alias is primary, they'll attempt…

I just tested it, and it looks as if that was fixed. It seemed to work for me.

Re: Emailing a one-time code is worse than passwords

#573

Earlier quoted context omitted.

Did people not realize they can save their 2fa token and just use that with a new authenticator? I haven't used a phone 2fa forever, but it was a much better system than this "email me a code" BS.

For a long time 2fa apps (other than Bitwarden and maybe some others) would lock you into the app and not let you export it. Websites don’t usually expose the text version of the code, just the QR.

It's easy to screenshot or physically print a QR code during setup.

Re: Emailing a one-time code is worse than passwords

#575

Earlier quoted context omitted.

What do you mean by real backups? What's stopping you from backing up your keys? Its up to the passkey "provider" to allow passkeys backup/sync.

Well, having your passkey provider blocked for doing that might stop you. https://github.com/keepassxreboot/keepassxc/issues/10407 Of course, they might just block you for not being on a whitelist of approved providers anyway.

The objection there was not to providing passkey backup. It was to doing it in plain text.

Re: Emailing a one-time code is worse than passwords

#576

Earlier quoted context omitted.

Vendor lock-in and lack of alternatives. 1Password used to work decently well before 2020. Now I have ~ 2k items in 1Password, distributed among two accounts (work and personal). Additionally, my spouse and I have a shared 1Password vault via the Family plan. There’s no way I’m going to migrate 2k items and two dozen devices to another vendor. If there were one that met my requirements to begin with.

Every vendor implements export and import. Why do you think you would need to manually migrate?

1Password has tons of features. No two vendors have exactly the same data model. Any of them might break on migration or worse, doesn’t exist on the target system.

For example, are my 2FA seeds going to migrate properly? How about the tags, attachments, sections, subsections, security questions and answers, inline Markdown notes, the HIBP integration, built-in overrides to fix known broken websites, workarounds I’ve learned for unfixed websites, shared vaults, recovering lost access to shared vaults, syncing, templates, custom integrations that I maintain [0], personal scripts, etc. etc.

Will it still be able to auto-fill into a web page? Into shitty, broken web pages? On Linux? On my Linux phone?

At the scale and depth at which 1Password is currently integrated into my spouse’s and my life, it’s difficult to consider migration anything less than a full weekend project.

I regret letting my spouse and myself lock into 1Password before it enshittified.

[0]: https://github.com/claui/aws-credential-1password

Re: Emailing a one-time code is worse than passwords

#577

Earlier quoted context omitted.

Did people not realize they can save their 2fa token and just use that with a new authenticator? I haven't used a phone 2fa forever, but it was a much better system than this "email me a code" BS.

For a long time 2fa apps (other than Bitwarden and maybe some others) would lock you into the app and not let you export it. Websites don’t usually expose the text version of the code, just the QR.

Almost all (not you, steam) allow saying "I cannot take a picture" or "Enter manually"

But you're right, it's not perfect but has gotten better. Just in time to be of no use thanks to email BS.

Re: Emailing a one-time code is worse than passwords

#578

Earlier quoted context omitted.

Did people not realize they can save their 2fa token and just use that with a new authenticator? I haven't used a phone 2fa forever, but it was a much better system than this "email me a code" BS.

For a long time 2fa apps (other than Bitwarden and maybe some others) would lock you into the app and not let you export it. Websites don’t usually expose the text version of the code, just the QR.

I recently switched from Authy to 1Password for 2FA, requiring me to set up every single website's 2FA from scratch, and I found that every website I use provides the text version of the code. It's hidden behind a "having a problem scanning the code?" link. I didn't need to take a single screenshot of a QR code; I was able to save the text version for them all. Next time I switch, it'll be easy.

Re: Emailing a one-time code is worse than passwords

#579
post #484

Earlier quoted context omitted.

To add, services account for that failure by introducing something worse: a customer service backdoor where you can get into an account with very weak or nonexistent authentication. With Amazon's live chat, someone was able to get into my account by providing an address in the same city as the destination of my latest Amazon order. You see this with 2FA since "sorry lol you've lost your account forever" isn't an opti…

Services that use passwords for login need to do that too, because people lose passwords. Even services that use login via emailed link need to do it because people do lose email access. Far too many people use the email provided by their ISP as their only email service, which can be very bad if they move to someplace that ISP does not serve or simply want to switch to another ISP in their current area.

The forgot-my-password email link has a customer support load very different from "I can't do 2fa because I lost my device".

And once you set up a customer service pipeline for it, you might accidentally create a backdoor that's far worse than forgot-my-password email verification: https://medium.com/@espringe/amazon-s-customer-service-backd...

Email account access is the closest thing we have to ubiquitous identity on the web. Users that truly lose access to their email account are in a catastrophic situation before they even think of whether they can access your service.

Re: Emailing a one-time code is worse than passwords

#580
post #518

Earlier quoted context omitted.

That doesn’t happen when you use Apple’s passwords ecosystem or 1Password. The backing databases are synchronized between devices.

And everyone knows that abuelitas in the global south, as a rule, own iPhone 16s and subscribe to 1Password.

There's no need to be snippy.

Those are the solutions I'm familiar with; there may be others. If Android and Windows don't already solve this problem in similar ways--which they might!--it sounds like an open opportunity for them.

Edit: sure enough, Android supports it: https://support.google.com/chrome/answer/13168025?hl=en&co=G...

As does Windows: https://blogs.windows.com/windowsdeveloper/2024/10/08/passke...

Post reply on HN