So the threat model is someone physically stealing your phone and guessing/seeing your password. The #1 proposed solution is a Yubikey. Can't they steal that too?
YK's FIDO2 action can be passphrase protected. Mine has passphrases for FIDO2 and gpg. So stealing it won't help anyone.
The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA
61–64 of 64 posts
Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA
#62What I missed from the article is the usual: biometric authentication is not secure. https://www.youtube.com/watch?v=tJw2Kf1khlA (Yes, I'm linking YouTube because unlike popular belief, some channels are actually informative, or some make it easy for us to understand the content.) I would never use my fingerprint for authentication, because it's a flawed concept. The problem is, that your fingerprint is not a passwor…
Biometrics are like identification yes. It checks that it's you. Now knowing that it's you, it retrieves a password stored on-device and uses the password for auth. The auth is using a password still. The password is just indexed on your face or fingerprint ID and only locally, on-device. That means the attacker would need the device to ever get at the password in the first place. Then they'd need to be able to break…
Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA
#63Earlier quoted context omitted.
It's common in London, phones are being stolen for the access to financial accounts, not the value of the phone itself. They steal the phone out of your hands while it is unlocked. For example: https://www.bbc.com/news/articles/cy8y70pvz92o.amp I'm not sure exactly how they get around security features, perhaps by social engineering customer support, if they have enough PII.
Uhm yeah in order to actually wire money in my banking app I need to input a fingerprint. Smart people developed these apps banks are not stupid. Obviously people can still kidnap you and torture you but that's no different from before smartphones.
Re: The Convenience Trap: Why Seamless Banking Access Can Turn 2FA into 1FA
#64Earlier quoted context omitted.
Seeing as we won’t agree on 2 and 3, let’s discuss 1. Your argument hinges on us getting access to a quantum computer that is stable enough for Shor’s algorithm to run invalidating RSA and ECC, current password hashes being updated using algorithms that are secure, or long enough, and a quantum safe algorithm not existing for PKi. Do you understand how this sequence of events is extremely unlikely, specifically since…
You want people to bury their head in the sand, and unwillingly accept the unnecessary risk for little reward.
So now we have Apple Google and Microsoft getting a standard together that is actually secure in 2025 and your response is that sometime in the future a computer that our best engineers and scientists still haven’t been able to even prove may even be feasible might be able to reverse a public key.
I also have a strong suspicion that the people that goes through the effort of even implementing Passkeys and those that care about security are a mostly overlapping set, so the likelihood of those public keys leaking in the first place is significantly lower the Bob’s hardware leaking my old mans one password he uses for everything.
The security improvement for 99.99% of the population from using passkeys just far outweighs your hypothetical future that will likely never happen.
I predict we will get AGI before a quantum computer that can reverse a public key, and we will have quantum safe public keys before that.