You're doing two-factor authentication wrong
theorangeone.net
theorangeone.net
I guess if you're some sort of public figure it might be, but selling blue badges to anyone kinda destroyed any credibility it had as a platform for those people.
Twitter is about there for me. If someone took over my account, Meh. I'd just create a new one. It's not tied to a real email anyway. I actually think I'm on my 3rd one now. Because I forgot which email I used to sign up.
Previously you had only the login and the password. Now, you need a phone and likely probably an app on the phone.
This whole push for 2FA is actually a push against individual password managers where users generate long cryptographically secure passwords.
In my opinion, learning to use a password manager has effectively eliminated dozens if not hundreds of passwords and user names that I would have had to remember and all I need to remember is my one password manager password and everything gets copied and pasted in automatically. Even easier on my phone with FaceID unlocking the vault.
But it is still a complication and disruption to previous sign in flows that I had to adapt to and maintain.
Generating passwords properly gets rid of need of any password manager while each password keeps being unique. It is useful if most of my devices for internets don't have any password manager implemented (example - any Blackberry/Symbian/Opera Mini)
But they have a "Skip" button which so far works just fine. And I'm very happy it's there. So regardless of other merits, at least Ubisoft did that right with UPlay.
But the biggest security flaw, it turns out, is systemic, not individual: people simply don’t care about securing their one measly vote as much as they care about securing $100,000 in their bank.
So while people were motivated to secure large individual balances, they were not motivated to secure their votes.
Which is why we have to force people to confirm their votes on another device, so that Apple or Google couldn’t theoretically steal the election by lying to you about who you voted for, let alone some random website like stackoverflow (which people trust in their moderator elections etc.)
It turns out that this is also necessary for Web3 — the current state of security is dismal, the vast majority of people don’t actually check they are interfacing with the right contract or calling the right method or sending the right parameters before they hit “Submit” to sign the transaction. So even there, people have to be forced to double-check the details on another device, depending on the value of the transaction.
For more info see my article from 2020: https://www.coindesk.com/tech/2020/03/12/in-defense-of-block...
Polygon is probably going to be the winning provider of the space: https://community.intercoin.app/t/polygon-overtakes-ethereum... (although there are smaller ones, such as Arbitrum, Cardano)
I imagine that, in the future, we will simply have an "embarrassingly parallel" set of append-only logs, which is already possible with projects like Hypercore. And we will run consensus with those.
As for your question - the way you have secret voting is by using ring signatures. (Monero has ring signatures.) You just have to indicate that you're part of a group, and that you used your one vote, but it doesn't say who you are https://en.wikipedia.org/wiki/Ring_signature
This was known since 2004, and doesn't require blockchains in fact: https://eprint.iacr.org/2004/281.pdf
A blockchain-based way would be to use a mixer (like Tornado Cash does) to mix up the tokens so each person still has exactly 1 but now it's harder to trace who has which one.
But I also hate to add a password for each shitty website. I also don't want to connect an account via e.g. OIDC with any of my important accounts. I think there is a product or at least a new common mechanic somewhere in this mess.
Unless you only access that site via public infrastructure like a library, but that might not be infrastructure that you want confidential information to run over, because everybody and the milkman has access to it. And even then, 1Password for example also has an online version that you can access in those cases.
My point from the root of this tree was that I do not want to make a shit travel (github asks me to prove identiny by mail > gmail asks me to prove my identity by phone > my phone is somewhere else because I am not addicted to it) just to have an ability to use my github from web-interface. If I can successfully use my bitcoins without any 2fa/totp security theater than github is just shitting me with no good reason for me and for my helloworlds collection.
Probably just saving cookies solves the problem of the shit travel, but since every few hours session of browsing makes me to store tens megabytes of cookies with no value to me (except of not un-logging from github) I use to clear all cookies every time I close my browser.
A paasword manager is also "your brain". A website can be happy with just a password.
For crying out loud, people don't need 2fa for a knitting forum!
No, it isn't a crisis if someone gets my credentials to the knitting forum, the pics of acrons forum, and the local 'reserve space at the county pool' website... all in one go.
I can just change them all at once, from the letter 'a' to the letter 'b'.
I've set the bar pretty low these days for "if you require a login, I go somewhere else" because there are plenty of places that just don't need it in my opinion.
To be honest, I class Twitter as one of those places; I go there to read certain information from specific "outlets" but Twitter as we all know have made it very difficult (as with other social sites of this type) to be read-only.
I dispute that. Does the Nintendo Switch have a password manager?
Trying to do 2FA correctly is one thing and trying to make your whole company do it correctly is a whole other challenge...
In Australia, for example, telcos get punished heavily for delaying ports but don’t get punished for unauthorised ports. This disincentivises telcos to perform any due diligence whatsoever. Up until a few years ago, anyone could walk into a telco and port any random number onto a new sim. These processes are improving, but sim swapping is still trivial.
Not to mention SMS is also an unencrypted medium.
I avoid using my phone number for MFA unless I’m forced into it (which sadly happens quite often).
Unfortunately these regulations now hurt the consumer more than they help. Imagine if you could transfer a domain name without a transfer code or confirmation from the owner or current registrar. That’s what phone numbers are like in Australia. I absolutely want my telco to deny a port without my permission, but regulation prevents them from doing this. Instead, I have to rely on every other telco in Australia doing their due diligence if someone tries to port my number. It’s a losing battle because my identity has been leaked several times in the past few years. I have to assume that at any moment my phone number will be ported away by a bad actor.
I believe this is being reformed to require explicit approval from the owner. But this is very late and inferior compared to other countries such as the UK with PAC codes etc.
I've done three: Telstra to A now defunct MVNO back to Telstra and now Aldi.
I have never been able to socially engineer the change without either other online proof of posession, or this SMS exchange. Never.
Maybe I just found providers who implemented tighter controls.
I wasn't clear, that I also believe the RATE of sim port attacks in Australia is far, far lower than in the USA. I don't doubt some happen, but I think we have less per head of population. In part, I think the 100 points checks and KYC plays to this.
[1] https://commission.europa.eu/law/law-topic/data-protection/r...
Then the most common TOTP app, Google Auth, didn’t backup your codes so that was pointless and user hostile. They fixed it but I mean damage done I guess.
I’m not gonna buy a hardware security key and carry it around for casual usage. I absolutely will never ever do that. For work I will because I need to get paid, but for every login? Give me a break. Once again security cannot destroy the user experience.
Here’s the actual right answer. Switch to passkeys and give up on all this poorly thought out junk.
Then goes on to explain why it is indeed better. Perhaps meant to write 'worse'?
Pretty sure this was FB training their facial recognition models.
- Alice is currently reusing passwords, and does not use 2FA. Alice decides to set up 2FA, but keeps reusing passwords. Not ideal, but net improvement.
- Bob is using a password manager, but does not use 2FA. Bob decides to set up 2FA, and sticks to using the password manager for storing password. All good!
- Charlie is using a password manager, but does not use 2FA. Charlie decides to set up 2FA, and afterwards drops the password manager, and starts reusing passwords. Not good.
My guess is the Alice and Bob cases would be the majority. Do you think the Charlie cases would also be common?
> It invites poor disipline with reusing passwords and with 500 pound gorilla corps, losing your second factor is losing your account permanently.
But I doubt that many people with good password discipline will revert to bad password discipline after enabling 2FA (the Charlie example).
Now what? I have to create a new life.
Alternatively, you get a new phone, install a TOTP app and scan or import your TOTP seed backups.
What seed backups?
FWIW, password reuse with MFA is not actually that much of a problem any more. Neither is rotation (which was show to be a net negative). There's a whole set of NIST guidelines on the topic.
It's pretty common to read about people fully losing access to their Google accounts and often only regaining it by using internal contacts at the company (or being shit out of luck). I don't think even supporters of 2FA can discount how difficult (or impossible) it can be to regain access to 2FA accounts for certain providers.