Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

621–630 of 816 posts

Re: Emailing a one-time code is worse than passwords

#621

Earlier quoted context omitted.

You don't, but with one services have a better guarantee that they are.

You’re falling for the exact “better security” fallacy I was trying to warn about. Security is not a rating, “better security/guarantee” is not a really meaningful phrase on its own, even though it’s very tempting to take mental shortcuts and think in such terms. Attestation provides a guarantee that the credential is stored in a system controlled by a specific vendor. It’s not “more” or “less” secure, it’s just what…

>You’re falling for the exact “better security” fallacy

How is it a fallacy? The rate of account compromises is a real metric that is affected by how good security there is for accounts.

Re: Emailing a one-time code is worse than passwords

#622

Earlier quoted context omitted.

What do you mean by real backups? What's stopping you from backing up your keys? Its up to the passkey "provider" to allow passkeys backup/sync.

Well, having your passkey provider blocked for doing that might stop you. https://github.com/keepassxreboot/keepassxc/issues/10407 Of course, they might just block you for not being on a whitelist of approved providers anyway.

Since you keep posting this link, I'll just keep saying it: there is no credential manager attestation in the consumer synced passkey ecosystem. Period. There is no way to build and allowlist, by design. The consumer synced passkey ecosystem is open.

Re: Emailing a one-time code is worse than passwords

#623

Earlier quoted context omitted.

Because users want the services they use to be good. They don't want to be sent phishing links from their friend's account that was hijacked by attackers.

I had a meeting with a public servant this morning. He is part of an organization that promotes multi-factor authentication and publicly endorses the view that users are stupid. The meeting was about him unable to test the APK of the new version of their mobile app. He felt embarrassed, his mobile phone is enrolled in the MDM scheme that disallows side-loading of apps. What I am trying to say is that assuming users a…

The solution here sounds like having a separate development device that is used to sideload test versions of the app. The idea is that devices may require different levels of security depending on how much can be accessed from that device.

Re: Emailing a one-time code is worse than passwords

#624

Earlier quoted context omitted.

I've been using Keepass for two decades and have never had a single issue. I would never recommend a browser plug in (too much attack surface area), and instead simply check the URL before having KeePass autotype. No clipboard. I think you're rejecting good solutions out of hand. Meanwhile...millions of users trusted LastPass. Twice.

> simply check the URL before having KeePass autotype. I’m not going to rely on myself never making a mistake. I want a solution that protects me even during stressful moments where I have a lapse of judgement and forget to check.

If you're not using KeepassXC's browser plugin (or are using KeePassX, which -IIRC- never had a browser plugin), then its autotype feature will check the title of the window that has keyboard focus when deciding which entry to use. If one or more matches are found, it will [1] also ask you to confirm which entry you're about to have the software punch in. If no matches are found, it will alert you to that fact.

You might find the KeePassXC docs about the feature [0] to be informative.

If you're going to complain that all a phisher has to do to capture a password is create a website with the same title as the official one, then my reply would be something like "Duh. That's what the browser plugin is for.".

[0] https://keepassxc.org/docs/KeePassXC_UserGuide#_auto_type>

[1] ...optionally, and on by default...

Re: Emailing a one-time code is worse than passwords

#625
post #65

Earlier quoted context omitted.

The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortuna…

yeah, IMHO the design was messed up by a few very influential companies "over fitting" it for their company specific needs but I don't think attestation per-se is bad, if you are a employee from a company and they provide you the hardware and have special certification requirements for the hardware then attestation is totally fine at the same time normal "private" users should never exposed to it, and for most situat…

>but I don't think attestation per-se is bad, if you are a employee from a company and they provide you the hardware and have special certification requirements for the hardware then attestation is totally fine

Perhaps I'm missing something, but I do think hardware "attestation per-se is bad. Just look at the debacle of SafetyNet/Play Integrity, which disadvantages non-Google/non-OEM devices. Hardware attestation is that on steroids.

As for corporate/MDM managed environments, what's wrong with client certificates[0] for "attestation"? They've been used securely and successfully for decades.

As for the rest of your comment, I think you're spot on. Thanks for sharing your thoughts!

[0] https://en.wikipedia.org/wiki/Client_certificate

Re: Emailing a one-time code is worse than passwords

#626

Earlier quoted context omitted.

Did people not realize they can save their 2fa token and just use that with a new authenticator? I haven't used a phone 2fa forever, but it was a much better system than this "email me a code" BS.

For a long time 2fa apps (other than Bitwarden and maybe some others) would lock you into the app and not let you export it. Websites don’t usually expose the text version of the code, just the QR.

I've never found a TOTP site that didn't also have a "click to show the code" option. It's usually in small print at the bottom, but it's there.

Re: Emailing a one-time code is worse than passwords

#627
post #231

Earlier quoted context omitted.

> Passkeys is the way to go. Password manager support for passkeys is getting really good. And I assure you, all passkeys being lost when a user loses their phone is far, far better than what’s been happening with passwords. I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money. I am waiting for the era when using passkeys is not depending from…

> I am waiting for the era when using passkeys is not depending from some big tech company. You can choose any credential manager you want to store your passkeys.

The maker of the credential manager is still a "big tech company", and there is still lock-in. Before I ever use any passkey solution, I would need to be guaranteed the ability to export and backup my passkeys and migrate them wherever I want.

My expectations for how long I intend to be alive and using the internet is much longer than my expectations for the continued operation and service of any particular passkey management software.

I already had to jump ship from LastPass after they were hacked. Imagine if they hadn't allowed me to migrate my passwords.

Re: Emailing a one-time code is worse than passwords

#628

Earlier quoted context omitted.

> I am waiting for the era when using passkeys is not depending from some big tech company. You can choose any credential manager you want to store your passkeys.

The maker of the credential manager is still a "big tech company", and there is still lock-in. Before I ever use any passkey solution, I would need to be guaranteed the ability to export and backup my passkeys and migrate them wherever I want. My expectations for how long I intend to be alive and using the internet is much longer than my expectations for the continued operation and service of any particular passkey m…

Bitwarden is a great option for you. You can even self host it!

Re: Emailing a one-time code is worse than passwords

#629

Earlier quoted context omitted.

That's fine, but Chrome has 67% market share, and the majority of people will pick the default option for passkeys if prompted. For passkeys to replace passwords it's got to be seamless and easily recoverable without compromising security.

Yes, it really is a shame that Google Chrome has dominated the market since the very first browser was created.

[deleted]

Re: Emailing a one-time code is worse than passwords

#630

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

How is it different from plain old password?

1) User goes to BAD website and enter credentials

2) BAD website use GOOD website to check if credential is valid

3) Pwned

It is just MITM attack. The moment you go to BAD and enter credential (password or one time code) you are done.

Post reply on HN