Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The HN crowd hates passwordless sign ins but most of us actually know how to keep our passwords secure, at least relative to the average user. Non-techies have their passwords leaked and identities stolen time and time again. And get frustrated when they keep forgetting their password. Biometric passwords are incredibly useful for these people.

Of course Apple, Google, Microsoft have to keep non-biometric password authentication. Otherwise a lot of people (including me) will have to simply stop using their products, not even because of privacy, just because I doubt a Linux computer without a camera or old iPhone model will work for them.

Some argue that users without biometric authentication will be flagged suspicious and pressured to hand over biometric data. But honestly, I think so many people will stick to regular passwords, and more will be physically unable to use biometric passwords, so it won’t work.

Overall I think having the option to use biometric authentication is a net positive. Companies want them to get user data, but non-technical people want them because (when done right) they’re a lot easier and more secure than passwords.



Passwords are extremely counterintuitive and require understanding of the architecture of the systems to make any sense of it. Why do you need a password to your phone and then why do you need a password for the apps and websites? Why do you need an SMS and why do you need a code generator? Why do you sign in into your Google account to sign in into Stackexchange? None of that makes unless you understand the distinctions between systems and all that happens when we race to make the experience seamless as if there's no distinctions. It's getting so messy that phishing becomes hard to detect even for the more experienced people, you simply follow the instructions of typing codes and clicking links.

It only makes sense to have a device that can identify you personally and then use that device to get identified to other systems. That's actually why anonymous accounts and fingerprinting are very effective in tracking people(remember that companies like FB can identify you without you ever creating an account with them).

Passwords only use is account sharing IMHO. Once everyone goes passwords-less, sharing a Netflix account will be a thing of the past for example. Maybe this is one of the motivations of the big tech but overall I think it's for the greater good and sharing a service will be served better through explicit means of sharing the service.


This sounds dystopian and also really bad engineering.

First, I don't want a single login for everywhere. For obvious privacy reasons, using multiple disjoint accounts is preferable.

Second, using a device to identify someone creates a single point of failure. That device will get stolen or will break at the most inconvenient time. The battery will run out. Or something else will happen.

This is far from theoretical. My phone died on a business trip. It turned into a nightmare because almost everything needs two factor authentication. It's really bad not being able to spend money you have. That is when I learned the value of cash.

The obsession with passwordless logins and 2FA is anti-consumer. It needs to stop.


> For obvious privacy reasons, using multiple disjoint accounts is preferable.

Actually, the reasons are not as obvious as one might think and not as preferable as assumed. Disjoint anonymous accounts are one of the core reason for all the problems we have on the internet(there are much more spammers and manipulators than there are whistleblowers).

I'm sure you are exposing corruption all the time or you are doing gay stuff in Iran but the majority of the anonymous activity is spamming, trolling or political manipulation.

If you say why you need anonymous account we might work out a solution for you.


Is this serious or a bad attempt at sarcasm?


I don't know why you think I'm not serious because trolls spam and political manipulation is a thing on the internet these days, Google it! Care to answer and further explain your arguments?


Because people tell you their name if they want to, and give you their thoughts if they choose to do so. Having your name available to all at any time and anything you've ever said regardless of context or without limits to the intended audience is madness. It's a freedom we should not be willing to give up so easily because of technology.

On top of that, having all that personal information available will actually increase the power of trolls and political manipulation, not to mention exacerbate identity theft, profiling, security and phishing problems.


You don't have to give your name to anyone. Single sign in implies a single person but doesn't need to have any more information on that person and even if it has the info doesn't have to share it with anyone.


It's really serious? Wow! Not even Microsoft TPMs write such nonsense.

Forcing people to have a single ID across the web is a terrible idea. Having multiple disjoint accounts makes it much more difficult to track your activity online. It's not worth killing privacy just to stop a couple of annoying spammers.

Of course Google/Facebook/Microsoft love the idea because it makes tracking user behaviour much more easier.


[flagged]


How does Facebook have this magical power for which you provide no explanation? Of course, there is no such magical power. The trick works if you allow it, that is unless you block it with technical means. After all, you are still in control of your computer, so if you block the information they use to track you, they won't be able to track you. Thus, it is not sufficient reason to force the implementation of a dystopian surveillance machine.


No, no magical tricks. They do device and browser fingerprinting, essentially they can detect you across the internet and in real life through your device networks, device identifiers like MAC address, device specs and configuration.


All of these information sources can be sanitized so that the entropy they give off is reduced. See efforts by the Tor Browser and Firefox on reducing the effect of fingerprinting. Additionally, your MAC address is not exposed over the internet, just to the next hop.

I'll repeat what I said:

> Thus, it is not sufficient reason to force the implementation of a dystopian surveillance machine.


[flagged]


See, this behavior is absurd in real life and I should have been able to avoid speaking with you so I don't waste my time. The anonymity gives you a shield against it and I don't think this is something healthy. Why I'm being called a troll for pushing an argument? Because of people like you, we can't have healthy arguments anymore because calling someone names without repercussions has become the norm even beyond kindergarten.


> Maybe you should study these things and come back later when you know what are you talking about?

You were extremely condescending and rude in your argument. That's why you were called a troll.


if we had a single sign in system, you would have been banned from the internet already :)


> It only makes sense to have a device that can identify you personally and then use that device to get identified to other systems.

What to do then if the device gets lost, damaged, soft-bricked, or worst case seized by the police?


You get a replacement if lost or broken. Then re-authenticate and restore from a backup. That's how it's done with iPhones.

And about the police, you destroy or lock your device. If that's not %100 secure, it's OK because that's part of the risks about going against the authority. Can you imagine revolutionaries not revolting because the police might hit back? The risk of being caught by the police is part of the outlaw experience and you will need to actively try to avoid it.


Who's providing the back up? How do you re-authenticate if you lost the thing you use to authenticate with?

It's easy saying it but I don't understand how you do those things. If the answer is you need a password to access the backup and to access an account to re-authenticate, I'm not enjoying the irony. If the answer is to trust a company like Apple, Google, Microsoft with the literal keys to my kingdom then this thing misses the point.

Currently I'm in control of my authentication, why would I hand that to some company and hope I don't annoy them enough to ban me, or just randomly cone up against their AI guardians.


On iPhone's case it's Apple and it is accessed by a password but in this hypothetical scenario it could be your own infrastructure or another device you own and that one can be password-less of that's your thing. Having one password to activate your authentication device is not a gin deal, it can be something like mnemonic seed etc.

The hazard is not one password but endless ways to authenticate through endless passwords.


> If that's not %100 secure, it's OK because that's part of the risks about going against the authority.

I was more talking about border control, which has been known especially in the US to believe that non-US citizens have no rights at all and even the rights of US citizens and permanent residents have limited rights.

And for what it's worth you can end up having your devices seized or being executed by police simply for the "crime" of being at the wrong place at the wrong time because the cops managed to fuck up the warrant or its execution by blowing up the door at the wrong address.

Police going rogue are a threat model everyone should be aware of these days.


I guess the US has its problems. If that's an issue, don't go there and if you choose to go, don't bring a device with you that you can't tolerate being investigated by the authorities.

It's unreasonable to say that all your problems in life must be solved by this one tech or it's not worth having it.


The problem with police overreach is not limited to the US in any way, it's global.

Anyway, all I'm saying is that people should not leave the police out of their threat model.


You can't solve police overreach through an app. There's no solution to the police overreach because they have access to rubber hose cryptography.


Your solution to insecure passwords is to hand the keys of the internet to a small number of companies? This is beyond ridiculous.

Not only this creates single points of failure, it also entrenches the already existing monopolies out there. (not to mention forcing everyone to dox themselves by providing biometrics)


Uhm, it's the public key, and yes pretty much anyone can have my public key. That's why it's called the "public" key. The private key never leaves the dongle, much like in a hardware cryptocurrency wallet.

I really fail to understand the whole confusion about FIDO, the amount of misinformation in the threads here (like in the parent comment) is staggering. It is a fantastic invention for expanding privacy& security. Maybe a lot of people confuse it with "log-in with X"?


Uhm, it's the public key, and yes pretty much anyone can have my public key. That's why it's called the "public" key. The private key never leaves the dongle, much like in a hardware cryptocurrency wallet.

This is not true for passkey, which the linked article is about. If you set up passkey on a site on e.g. your Mac, the credentials will be synced through iCloud and you can also use your iPhone or iPad as an authenticator. This raises the questions of the grandparent comment:

1. What if a FAANG company nukes the account that you use for credential syncing?

2. What if a FAANG company has access to your private keys?

In the case of Apple, I think (2) is covered. They use iCloud Keychain, which is already end-to-end encrypted. But I am not sure about other companies (Microsoft, Google), does the standard require end-to-end encryption of key material?


Seems like they will leave up security to the OS vendors? From the white paper:

We expect that FIDO authenticator vendors (in particular those of authenticators built into OS platforms) will adapt their authenticator implementations such that a FIDO credential can survive device loss. [...]

Just like password managers do with passwords, the underlying OS platform will “sync” the cryptographic keys that belong to a FIDO credential from device to device. This means that the security and availability of a user’s synced credential depends on the security of the underlying OS platform’s (Google’s, Apple’s, Microsoft’s, etc.) authentication mechanism for their online accounts, and on the security method for reinstating access when all (old) devices were lost.

https://media.fidoalliance.org/wp-content/uploads/2022/03/Ho...


> Seems like they will leave up security to the OS vendors?

Is it possible to be otherwise?


Tying logins to biometrics is a terrible idea.

Forcing all online logins to comply with the wishes of 3 tech giants is even a worse one.

This has nothing to do with privacy. It's about existing monopolies entrenching their monopolies and keeping competition out.


Yes, the private key leaves the dongle. FIDO gave up on that secure idea. Go read the FAQ on multi-device FIDO. https://fidoalliance.org/faqs/#multi-device-fido-credentials


Since when does "if you want you can copy the private key out" mean that you have to do that? What kind of logic is that?

Similarly I can say that passwords suck because there are (entirely optional) centralized password managers. Passwords are unsafe because you can voluntarily share them! Do not use passwords! /s


>Non-techies have their passwords leaked and identities stolen time and time again. And get frustrated when they keep forgetting their password. Biometric passwords are incredibly useful for these people.

In other words, broad technology adoption will always dilute and degrade the quality of different technology solutions.


People will get even more frustrated when their flimsy physical authenticators break down. Passwordless authentication is perfectly okay for a service like a physical bank, employer etc. that can always check your identity and re-enroll you via some other means if need be. It's a disaster in the making for something like Google, Facebook, MS etc. etc. that offer no such thing. Make no mistake, the same people who pick weak passwords today will neglect proper care about any kind of disaster recovery scenario.

The best you could do is use a "software-based" or "virtual" authenticator that explicitly refuses to protect against a user cloning and subsequently restoring its identity, at least as a last resort. Not good enough for bank payments, ofc. but plenty usable for everything else.


> most of us actually know how to keep our passwords secure, at least relative to the average user.

I'm an IT professional and despite using a password manager, I still prefer a physical security solution to a cybersecurity one. An attacker might be able to dump unencrypted secrets from my password manager, but they'll have to pry that U2F token out of my cold dead hands.

The password field in its current inlined form has to go in one way or another.


> but they'll have to pry that U2F token out of my cold dead hands.

That is a trade off between attack surface and difficulty of the "hack" though. Depending on who and where you are, getting your physical token by force is trivial. If your token is important enough, there will be plenty of people that won't shy from using violence.


Getting a password or a PIN code to a smart card by force is trivial, too. Even if one's physical wellbeing is protected by law, they can still be jailed[1] for failing to provide a password, even if no such password exists.

The previous guy who educated me about rubber hose threat modeling later turned out to be running a drug dealing operation[2].

[1] https://www.saunders.co.uk/news/prosecuted-for-your-password...

[2] https://www.newsbtc.com/all/douppikauppa-darknet-drug-lord-a...



I use for some websites a Yubikey. But for me it feels very "blackbox like". I did read about a lot of functions on the internet, but I'm affraid to play with it, because I won't break anything. Also in the end, there is allways a second password for emergency. So if your password list leaks, the emergency password leaks with it for most people I guess.


> Some argue that users without biometric authentication will be flagged suspicious and pressured to hand over biometric data

The distinction is about the usage of modern technologies, not handing over biometric data. There will come a time where you will need to use a device with a Secure Enclave or a TPM. That device will keep biometric data on device. You will not hand in the data, you will have to use the feature.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: