Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

721–730 of 816 posts

Re: Emailing a one-time code is worse than passwords

#721
post #65

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortuna…

I thought Apple decided not to utilize the attestation field, is this not true?

Re: Emailing a one-time code is worse than passwords

#722
IF everyone switches to PASSKEYS, hackers are going to focus exclusively on them and they WILL find a way; then everyone will be FUBAR. Worse, BIG TECH is not going to take responsibility. THAT and AI? PROBLEMATIC. Nothing is foolproof. However... Proper password protocol must be taught.Once upon a time, people had password hints. Why not tech a combination of that and proper passwords?

Re: Emailing a one-time code is worse than passwords

#723
post #698

Earlier quoted context omitted.

And I come back to: if it would never work, why not drop support? "We pinky promise" is just not good enough.

Is there a difference? It's a field in the response payload that nobody is filling out except the corps that need it. Would it make you feel better if they moved it to an appendix and called it an optional extension?

> Would it make you feel better if they moved it to an appendix and called it an optional extension?

That kind of thing can make a huge difference once this standard starts becoming e.g. required for government procurement.

Re: Emailing a one-time code is worse than passwords

#724

Earlier quoted context omitted.

This argument is ridiculous and purposefully inflammatory. The issue at hand is the requirement for client attestation while using passkeys. So in that light, can you describe for us the scenario in which grandma, who is undoubtedly using passkeys on an iPhone or an Android, looses all her money simply because someone, somewhere else is using a passkey without attestation? You can't, because the vendor lock-in create…

> The issue at hand is the requirement for client attestation while using passkeys. There is no attestation in the consumer synced passkey ecosystem. Period.

Can you say "There will be no attestation in the consumer synced passkey ecosystem. Period."? That seems to be the concern, not what exists today.

Re: Emailing a one-time code is worse than passwords

#725

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

Re: Granny - Pew Research about Online Scams, granny is far less likely to lose her account (15%) than an 18-29 year old (26%). If she's upper income and white even less likely. Similar trends with falling for large numbers of scams. People who've had 3+, granny (19%), 18-26 year olds (24%). [1] The survey notably has the same perception results. Society views the youth as mostly immune from scams (believe only 22%), yet fall victim to them (26%), while worrying about old people (believe 84% fall for them), who actually don't fall victim that often (15%).

Most of the time, re: granny, women are targeted a much greater amount because of supposed weakness and vulnerability (report 2/3, victim 2/3), yet males send much larger amounts of money. ($112 vs $205) [2] Too be fair though, old people do tend to lose more with scams. Granny would probably lose $300 on average vs $113 for a 18-24. Conflicting numbers on the money #'s though, so some of that depends on which survey you ask.

Old people also tend to write each other a lot of cautionary warning stories such as the AARP article on Stan Lee's swindling in old age (security guard, "senior adviser", "protector", and daughter). [3]

Old people get a bunch of grief, yet old people are actually less likely to fall for the scams.

Also, if she's a retiree in Miami Beach, more likely to be targeted (Adak, AK; Deepwater, NJ; then Miami Beach, FL are the worst for scams.)

[1] https://www.pewresearch.org/internet/2025/07/31/online-scams...

[2] https://bbbmarketplacetrust.org/wp-content/uploads/2025/02/N...

[3] https://www.aarp.org/entertainment/celebrities/stan-lee-elde...

Re: Emailing a one-time code is worse than passwords

#726

The attack pattern is: 1) User goes to BAD website and signs up. 2) BAD website says “We’ve sent you an email, please enter the 6-digit code! The email will come from GOOD, as they are our sign-in partner.” 3) BAD’s bots start a “Sign in with email one-time code” flow on the GOOD website using the user’s email. 4) GOOD sends a one-time login code email to the user’s email address. 5) The user is very likely to trust…

>"I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money." More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. I live in a third world country and even 2FA simply isn't viable for me due to how frequent phone robberies are. I've had to do the pro…

I feel like this is a really strong justification for duress passwords. Register a duress password with your phone or bank account, and if you ever enter it, that system will take whatever actions you want - call the police with your location, display a fake balance of a few hundred dollars, switch to a fake email account, hide your crypto wallet app, whatever.

Re: Emailing a one-time code is worse than passwords

#727
post #609

Earlier quoted context omitted.

I want to like passkeys but I haven't had any success getting them to work. Every time I click on "sign in using passkey" both my browser (Firefox or Chrome, on Android/Win/Mac) and Bitwarden are like "no passkeys found" and I'm never given an option to create one. I feel like I'm doing something stupidly wrong or missing a prompt somewhere, or maybe UX is just shitty everywhere, but if I, a millennial who grew up pr…

I've seen that kind of comments multiple times, and I don't get it. I use Yubikeys, and passkeys just work. On Chrome, Firefox and Safari, both on macOS and Linux (specifically Alpine). I also tried with iPhones (for my family), and it also just works. I haven't tried using an Android device, is it what you are trying?

That might be the delta. I'm not using a hardware key (well, not a YubiKey). I'm using just my phone or browser.

Re: Emailing a one-time code is worse than passwords

#728

Earlier quoted context omitted.

The website is abc.com the link in the email is abc.com

unless the product manager decided the link in the email is track.monkey.exe/sus/path/spyware?c=behhdywbsncocjdb&b=ndbejsudndbd&k=uehwbehsysjendbdhjdodj or something 2x–3x longer

The question was "How do you know the email comes from that website? "

And the answer was, I can find out if the email is from abc.com by looking at the link, which should also be abc.com

I don't click in "track.monkey.exe". I don't click tracking links. I pay a lot of money for my newsletter provider because I can turn off (most) tracking links.

Re: Emailing a one-time code is worse than passwords

#729

Earlier quoted context omitted.

The website is abc.com the link in the email is abc.com

The link in the email is a mailchimp wrapped tracking link with a gibberish URL. What now

I don't click the link. Simple.

Track someone else.

Re: Emailing a one-time code is worse than passwords

#730
post #547

Earlier quoted context omitted.

The link in the email is a mailchimp wrapped tracking link with a gibberish URL. What now

Or the email is rendered HTML, where the expected URL is used as the text for an anchor whose href is the malicious site.

Pro tip: Hover over the link an check the URL. Or look at the source.
Post reply on HN