Live data from Hacker News

Emailing a one-time code is worse than passwords

blog.danielh.cc

761–770 of 816 posts

Re: Emailing a one-time code is worse than passwords

#761
post #333

Earlier quoted context omitted.

That’s a lot of anger without a substantial argument. For Apple users, for example, the user experience is very smooth and the mental model is “I use iCloud to store my passcode just like I use iCloud to store my passwords”. If you use 1Password, you’re changing iCloud for 1Password instead.

"You lost me the moment you mentioned iCloud". At least that's the way the majority of people I know react to this line of thinking. The "cloud" is still mysterious and complicated to a good number of people. Passwords are easy to understand.

Yeah that's right! If you simply say that this syncs to all my devices, it papers over, or abstracts if you will, the complexity of: secure enclaves/TPMs, symmetric sync keys wrapping asymmetrically encrypted passkeys, resident keys that support backup, keys that do NOT support backup, how biometrics are used, etc. etc.

With a password, I can write it down on a piece of paper and put it in my safe.

One of these systems is not like the other.

Re: Emailing a one-time code is worse than passwords

#762
post #755

Earlier quoted context omitted.

Yeah Microsoft is so annoying. It's also kicking me out every day now (with this passive aggressive "hang on while we're signing you out" message). On M365 business with Firefox on Linux with adblocker. I hate using their stuff so much.

Same has been happening for for a few months. I get thrown out of all o365 services multiple times each day.

Yes me too since a couple months :( So annoying. It doesn't of course happen on Windows.

It started with OneNote web a couple years ago. Every day that gave a popup "Your session needs to be refreshed) and it would reload all over again. Microsoft don't bother to make a OneNote desktop app for my platform and the web version is really terrible anyway (you can only search in one tab, not a whole notebook). So I moved to self-hosted Obsidian which I'm really happy with. Now I can basically see myself typing in a note from another client.

But replacing Microsoft for email is another topic.

Re: Emailing a one-time code is worse than passwords

#763

Earlier quoted context omitted.

Strawman? We are talking about this link, right, the one that says: > I've already heard rumblings that KeepassXC is likely to be featured in a few industry presentations that highlight security challenges with passkey providers, the need for functional and security certification, and the lack of identifying passkey provider attestation (which would allow RPs to block you, and something that I have previously rallied…

Yes, read the quotes you took again. Attestation is not a thing currently. There is legitimate discussion about how to handle shitty password managers. If LastPass shits the bed again, it would be great to have a mechanism for others to block it or at least know that due to a major incident, keys from that tool are week. Debian OpenSSL keys were vulnerable for a long time and being able to know and alert or block pri…

> If LastPass shits the bed again, it would be great to have a mechanism for others to block it

And by the way, if and when something like that does happen, what's the user supposed to do if they suddenly find their passkey provider has been blocked?

Re: Emailing a one-time code is worse than passwords

#764

Earlier quoted context omitted.

If a website says "Do this" and you're the person who follows random websites against security practices, because you believe in authority, a password manager does not help. You will open the password manager, search for GOOD.com and put it into BAD.com and be angry that your password manager can't do that for you. "Any human can be tricked, no matter how smart they are." and "A password manager will protect me from…

> you're the person who follows random websites against security practices, because you believe in authority There are many reasons why such lapses of judgements happen, even to people who don’t believe in authority. For example, the fact that any human can be tricked. > Don't work together. Either everyone can be tricked or not. The password manager protects me from filling my password into the wrong site. The passw…

So everyone can be tricked except you, because you use a password manager.

Re: Emailing a one-time code is worse than passwords

#765
post #3

I thought this was going to be about Passkeys. Maybe if the FIDO Alliance can stop being obstinant and allow real backups, I'd be all in on them.

But if you could back up a passkey, wouldn't the key just be a password? (I do agree with you about backups being essential, but my conclusion was "the idea is fundamentally flawed," rather than "it's one tweak away from greatness.")

Passkeys solve phishing by being domain bound and never exposing the private key. It's a huge improvement!

Re: Emailing a one-time code is worse than passwords

#766
post #65

Earlier quoted context omitted.

The problems of Passkeys are more nuanced than just losing access when a device is lost (which actually doesn't need to happen depending on your setup). The biggest problem are attestations, which let services block users who use tools that give them more freedom. Passkeys, or more generally challenge-response protocols, could easily have been an amazing replacement for passwords and a win-win for everyone. Unfortuna…

I want to like passkeys but I haven't had any success getting them to work. Every time I click on "sign in using passkey" both my browser (Firefox or Chrome, on Android/Win/Mac) and Bitwarden are like "no passkeys found" and I'm never given an option to create one. I feel like I'm doing something stupidly wrong or missing a prompt somewhere, or maybe UX is just shitty everywhere, but if I, a millennial who grew up pr…

I use Bitwarden in Firefox and passkeys "just work" on Linux, Android, Mac, and Windows. Previously, I used the extension in Chrome (Linux, Android, Windows).

The only relevant Bitwarden setting appears to be "Ask to save and use passkeys" under Notifications. I do turn off the browser's built-in password manager, though I believe anything else relevant I have at default. If you have those and they still aren't getting saved, then I'm at a loss, but wish I knew why they don't work for you. In Bitwarden, you can see if there's a passkey saved in an entry, as the creation timestamp is shown right under the password field and editing an entry also allows deleting a passkey.

Re: Emailing a one-time code is worse than passwords

#767

Earlier quoted context omitted.

What instance have you seen where BigTech opted for control with no monetary incentive?

There is already an example of Microsoft selling passkeys with their own "secure (tm)" stamp on them, and not accepting anything else just a few comments down. Even if there wasn't already an example, it's easy to turn control into a revenue stream at a later time.

That is for their enterprise SaaS, and has an obvious profit motive (I.e. bundling). Do you think Chrome is going to start charging for using their passkey storage and then kick all the other apps off Chrome?

> Even if there wasn't already an example, it's easy to turn control into a revenue stream at a later time.

I think you’ll have to justify or qualify this a bit. If Google forces every website on Chrome to have a red background, how do they turn that control into a revenue stream later on?

Re: Emailing a one-time code is worse than passwords

#768

Earlier quoted context omitted.

> you're the person who follows random websites against security practices, because you believe in authority There are many reasons why such lapses of judgements happen, even to people who don’t believe in authority. For example, the fact that any human can be tricked. > Don't work together. Either everyone can be tricked or not. The password manager protects me from filling my password into the wrong site. The passw…

So everyone can be tricked except you, because you use a password manager.

I literally wrote in my last sentence that I can still be tricked.

Re: Emailing a one-time code is worse than passwords

#769

Earlier quoted context omitted.

So everyone can be tricked except you, because you use a password manager.

I literally wrote in my last sentence that I can still be tricked.

The excuse me, I read the last sentence differently.

Re: Emailing a one-time code is worse than passwords

#770

Earlier quoted context omitted.

>> Did people not realize they can save their 2fa token and just use that with a new authenticator? What's 2fa token? Is that an AI thing? AI uses tokens. Or a crypto thing? Do you need one of them "nonfungible" tokens? And what's an authenticator? I have MS authenticator for work, but it uses 2 digit numbers, are those tokens?

Not sure if I'm missing a joke, but the 2fa token is a secret that you stick in your password manager and sync (or otherwise send) to other devices so that your 2fa is not bound to a particular device. My password manager lets me view the 2fa secret as if it were just another password.

Yes, I was joking. I'm not up on all the options and I'm an engineer who read HN. What chance does Joe public have of making sense of all these things?
Post reply on HN