Passwordless: a different kind of hell?
jcarlosroldan.com
jcarlosroldan.com
First I had to log into ebay - no problem, got my password manager right here, as soon as I unlock my phone with my fingerprint. Now I'll just key in my 12 character, randomly generated password with mixed case letters, numbers and symbols.
Then ebay decided they wanted to send me a code by SMS. I'd never enabled that security option, but whatever. I can do that, quick fingerprint to unlock the phone then key in the code.
Then I chose to pay with paypal, requiring a second password. And a 2FA code, this time from a TOTP app. For some reason paypal ask for TOTP every time. Easy enough, quick fingerprint auth then just key in the code.
Then I told paypal I wanted to pay by card, as I always do. They redirected me to my bank, who asked me to use their mobile app to authorise the payment with my fingerprint. After unlocking my phone with my fingerprint, naturally.
Clearly, the days when businesses thought online shopping ought to be low-friction are long gone.
Now they only sell (arguable mid) pizza, but when I order there it’s delightful (to use an overused 2023 marketing buzzword)
(I too eat Domino's on the odd occasion the app doesn't take long enough for me to change my mind).
I worked in a Pizza Hut delivery place when I was in college. I just took my son back for a campus visit and yeah, 30 years later, its still there - same location and save a few minor changes, the building still has the exact layout. A testament to whoever laid out the original floor plan.
To be fair we don’t have many fast food pizza chains in my country, it’s mostly dominos and a few small ones (with abysmal online order experience)
They’re still the worst about it AFAIK but more of their competitors now do that at least once an order now, too, so the difference isn’t as large.
That being said, I feel the parent’s viewpoint is naively idealistic, the payment industry is huge with many players and most attempts at new standards or interoperability are by people trying to get a cut of the action, no one is going to adopt a new standard unless they feel they absolutely have to.
ApplePay is pragmatic in that it largely hooks into the existing CC systems and thanks to Apple’s market size they have enough clout to convince people it’s worth the effort.
A whole new standard just for the “general good of the public” will never get any traction without regulation, and in places like the U.S. where bribery is essentially legal (so long as you call it lobbying), any new regulation like this faces an extreme uphill battle to being introduced except where someone standing to make lots of money is behind it.
Do you actually have to give them the card? Or is it only stored somehow on the phone? I wonder how this works exactly.
When I replaced my old iphone with a new one, I did the whole "transfer everything" dance. Waited around for two hours (didn't restore from icloud, but transferred from old to new), and still had to manually add my CCs to Apple Pay again.
Apple then checks if your card issuer has ApplePay enabled and if so provisions a “virtual” card which is what is stored on the device’s Secure Enclave.
I also just checked my banking app quickly which can initiate the adding of the card to wallet, showing the wallet’s add card screen with the card holder name and the last 4 digits and asking if you want to proceed.
There is no way to see what the full virtual card number is, so there is no way to use this virtual card aside from tapping your phone on CC machines or using websites which have set up ApplePay as a payment method.
CC machines don’t actually have to support ApplePay specifically, as long as it supports tap to pay without insisting on a PIN, then ApplePay works with it. In essence your phone’s NFC exactly implements the same capabilities and protocols as NFC chips on normal credit cards.
IIRC it's not exactly the same. One user-facing example where things are different is that contactless payments with a regular credit card have a 50 € maximum. If there is a limit when paying with the iPhone, it's much higher.
I also seem to recall that the merchant's payment contract must support this, but I'll have to confirm with a colleague. Although Apple Pay support is very common where I live, it did happen a few times that some restaurant's terminal accepted VISA contactless but not Apple Pay.
I've also had a situation where my CC is set up to not allow payments outside my country. Payment with Apple Pay was denied as being "out of country", whereas the physical card worked fine. The store is from a big national chain, in the heart of the capital city.
I’m pretty sure that the limit amount before PIN verification is required is embedded in the NFC, or checked online or something. Both my credit cards have limits of R500 (~26USD) after which it requires I enter my PIN after tapping it.
For one of my credit cards I’m able to pay it off with my other credit card and I have in the past tapped my iPhone to do so for payments over R50,000 (~2600USD), I don’t think there’s a limit.
However, the biggest grocery retail chain here initially had a very annoying “custom” rule on their CC machines where it would ignore the card limit and insist on asking for PIN for any payments over R500, which would cause ApplePay tap attempts to auto decline, they eventually fixed this.
The out of country issue sounds like a configuration issue with your bank or that particular merchant. My cards by default disallow use out of country and I’ve never had an issue tapping anywhere with ApplePay.
Apple has issues with privacy, but I don't really see how this is one of them.
"Somehow" their information makes it around? No, you have to add them, yourself, on every device you use them from, individually.
When you use a 3rd party payment provider like PayPal it does a really good job of forcing all of this to be automatic compared to things trying to autofill custom forms just because it's integrated by the site instead of the user. MFA hell is starting to erode that actually being easier though and now there is more and more often no simple approach left.
Still, PayPal is an absolute last resort for me.
Want to have charges go direct to your bank for 2 weeks ? you move it up on the list.
Want to try a new card but are not sure you'll keep using it ? add to the wallet and move up or down depending on how much you want to use it.
And it also managed subscriptions.
It is now a steaming pile of garbage for so many reasons, and it has always been a death trap for any small merchant, but they gave a fairly good shot at the wallet side of things. Good luck getting Nintendo for instance trust any other third party wallet system.
I don't need to worry about my details still being with that merchant. I don't have to worry about the merchant's convolution and likely-illegal cancellation process. The only negative I can think of is that any dispute has to go through PayPal, and while I've never done it I would bet money they are going to be skewed more in the merchant's favor than the credit card company. But that being said I have had fully legitimate chargebacks (as in not "I want a refund and they said no" but "this is a fraudulent charge I never agreed to") get denied and reversed by Discover so that's not a 100% certainty either.
I never receive money through PayPal so while I've read all the same horror stories everyone else has, that doesn't seem likely to affect me. My biggest gripe is the full-screen advertisement for whatever service they're pushing every time you log in on the website.
Or you are saying it’s not worth reducing your usage of PayPal unless you get rewards?
First it can pay directly from a bank account.
Second a lot of countries don’t have many options other than PayPal.
I got fed up and opened a refund ticket with paypal describing the problems and within 30 min the merchant contacted me promising to send the missing items and refund 20% of the cost if i closed the ticket in paypal.
The aim is not "profit" but to get the deserved attention and bypass clear stalling tactics like having to prove a negative. Needles to say that I Did not ever use that merchant again.
They owned PayPal for a while, so it was heavily promoted. It's still their first choice AFAICT.
The most glaring odd thing here is that you apparently don't have your password vault available on the same machine you're shopping from, which seems odd to me. Even so, if I went that route it'd still be easy b/c with the Apple ecosystem, the clipboard is shared between devices. One can copy a password from the phone and paste it on the Mac.
The tl;dr here is that I really don't understand why you had to retype your password. I never type my strong passwords. Why would you put yourself in a position where that's required?
Finally, when I pay via Paypal using my Amex, I never have to re-auth to Amex. It just flows through. So it sounds like that's something you've chosen to set up, not something inherent to the process.
Likewise I've used a half dozen different cards and multiple bank accounts through PayPal for the last couple decades and can't remember the last time I've had to reauth on any of them during a checkout.
That one's on me, yes. The Yubikey I needed to unlock the password manager on the PC was upstairs and I couldn't be bothered to get it, so I used my phone instead.
(Why was the yubikey upstairs? Well you see, that's where the fireproof safe is. But I can't blame ebay for that, so I didn't mention it)
If the machine with the passwords is less exposed it's on average a lot safer (but now you have the problem of keyloggers of course)
To be fair to the parties involved, they might well blame "EU strong customer authentication rules"
I can often go through an entire sign-up, entering shipping, and payment, at a new site, without typing a single thing.
If someone has pwned my 1Password I don’t really care if they log on to my Discord or order a limited amount of crap on Amazon because I am in much deeper shit at that point.
Oh, wait: Steam has them I guess. Every so often (once every few months?) I have to type in one of their codes.
I did just check and I guess I could be doing this with non-sms codes if I added them to my password manager. If I had more than just Steam that used them, I’d do that.
Always the tradeoff with Apple is choice and flexibility versus a seamless and pleasant user experience.
I’m terrified of losing access to all my stuff because of forced 2FA I never signed up for. I get that it’s more secure, but it can be secure to the point of having unrecoverable data. All it would take is someone carelessly deciding to get a new phone number. I have a friend who recently talked about wanting to get a new number with his new phone. I asked about 2FA and he seemed to have no knowledge of it and said he didn’t have anything like that. He kept his number, but if he didn’t, I could see him easily getting locked out of his Apple account (which he has), and his bank.
If you have recovery keys enabled, it’s a different story. Enabling screen clearly states that you can get locked out of your account without your recovery key. You can set up recovery accounts too, like those of your family members.
Then 1 yr later a hn thread will remind you to try to log into your google SSO and.. bam it works. And you still have no idea why ALL of your g servces (domains, email, gphone, etc) were disconnected a year ago.
1) I’ve never ever heard Apple lock someone out of their Apple ID. Maybe they are obligated to do it for law enforcement in US but even none of that. Meanwhile I’ve heard a ton of stories of Google locking people out of their accounts.
2) The convenience of using Safari, with 2FA and passkeys set via iCloud Keychain is too good to ignore. Literally 1 click (passkeys) or 2 clicks at most, authenticated with Face ID.
So I’m using this setup rn. You can set custom domains with your iCloud email too.
But.
Those synced passwords are a huge, juicy target. Someday, someone is going to get them. This process is a vulnerable mess.
I have no words to express how much I hate this.
https://en.wikipedia.org/wiki/Strong_customer_authentication
And a credit card I've got recently also asks for a second code, after the 3ds code.
No, it's the shop that decides actually. More and more accepts do direct payments from card numbers without additional checks, by the way.
Have never seen that with VISA or MC.
I'm not sure what triggers it.
My credit card card [1] has fundamentally changed my online purchasing experience as it bridges what I feel is a gap between new payment methods (Apple, Google, et al) and classic payment methods (CC).
An ounce of prevention is worth a pound of cure.
When I purchase something line, I create a new one-time card (three taps on my phone) and use that new, valid CC for purchasing. Everybody takes a CC. The card is instantly deleted after purchase, and I don't have to worry about my paypal account, apple pay account, google wallet account, ghost subs, account hacks, identity theft -- the works.
Paypal absolutely lets you stop recurring payments unilaterally on their side. I use Paypal for subscriptions wherever it's offered precisely for this reason.
https://www.paypal.com/us/cshelp/article/what-is-an-automati...
I think it maybe only shows companies you had recent transactions with.
In 2023, I had a fraudulent $0.99 Paypal Automatic Payment for "Domain Name Forwarding - Renewal" from a company (DomainsPricedRight/OwnMyDomain aka GoDaddy) that I last did business with in 2005. Yes, 18 years prior.
I was able to 'deactivate' the 'subscription' on the Paypal site after I noticed the charge but I don't think automatic payments existed on Paypal in 2005 and I'd certainly never signed up for it.
The original 2005 business I did was a one time domain purchase that was transferred to another registrar within a year.
It was real fun to also see on Paypal that I could have been fraudulently charged up to $10,000.
It's kind of scary to think that any company I've done a Paypal transaction with could maybe do the same thing (or any of the companies that eventually acquire their merchant accounts...)
https://www.paypal.com/cgi-bin/webscr?cmd=_manage-paylist
[ EDIT: which redirects to the one you cited, so forget my attempt to be less wrong ]
I also don't do this on my phone, but on a regular PC.
https://www.theguardian.com/money/2022/mar/14/uk-shoppers-fa...
https://www.visa.co.uk/pay-with-visa/changes-in-payment-secu...
I don't know the details of when it is and isn't required. I am asked pretty much all the time for transactions using my Danish cards, and only some of the time for the British cards.
I do the same. Too many times I've had major issues trying to buy stuff on mobile so I just stopped doing it like 8 years ago. Literally the only thing I pay for with my phone is my hockey sessions via Venmo.
There are also authenticator browser extensions so you do not have to use a phone app for those either.
The software I use for the SMS codes is KDE Connect and SMS code.
https://www.cnet.com/tech/tech-industry/ebay-picks-up-paypal... - August 2002
The seller is motivated to make the buying process as easy, fast, and uncomplicated as possible. This is a direct correlation with how many things they sell, and in response how much money they make.
On the other hand - consumer opinion and regulation forces them to ensure that the buying process is secure, that someone else isn't buying things on your account, that they have proper logging of what goes on, etc.
The seller shouldn't "Fix" the buying experience by removing the security aspects of it. They should fix the buying experience by using modern authentication like passkeys and ensuring that their applications and sites support password managers.
Of the two applications I use for the SMS flow, one is generally useful to have anyway. The authenticator extension or an app is absolutely necessary for this type of 2FA and the alternative to some app is to not use 2FA at all or use SMS authentication.
Is this a native phone feature or an app? You're lucky if that's the only place it sends notifications.
I'll happily take this shit-show cacophony of various 2fa methods and authentication types if nobody is stealing money from my bank account or ordering stuff on ebay on my behalf.
The flip side of this - is that if companies properly setup auth and allow you to use username+password (or passkeys) and a TOTP method then this is all basically copy/paste from your password manager or verify on your phone and the process is super easy.
Even better: I wouldn't care about people stealing money from my bank account if cleaning it up and making whole was my bank's responsibility and not mine or some hapless vendor. Neither I, nor store vendors should have to put up with the "shit-show cacophony." The bank's entire reason for existence is to secure access to my money--it should be entirely their problem.
How is that possible?
I bought some lottery tickets online for a present to myself and the experience was smooooth. No cart, no checkout steps, no need to create an account, there was a QR code right next to the tickets that I had to scan with my banking app to buy them right here, right now.
"BTW, for your own safety, we implemented two factor on your account, and tied it to your old phone. Wait, you don't have that phone anymore, cause it was something like a 10 yr old retirement that you never obsessively check? And we didn't give you the option for an email? Or even warn you? Too bad. We now no longer accept logins for your own money."
Although that's roughly how the Wikipedia entry[0] summarises it, the actual wording of the story indicates a slightly different issue:
> for he could not frame to pronounce it right.
It's not a spelling difference per se, it's (AIUI) that the Gileadite pronunciation uses a phoneme that was not used at all in the Ephraimites spoken language, so an Ephraimites soldier was literally incapable of pronouncing the word "correctly".
e.g. How some spoken dialects/accents do not use a rhotic "r", or do not distinguish between "l"/"r", or are not tonal languages. If you have not already learned how to make that specific sound, and distinguish it from the other one, through repeated practice, you will be unable to replicate it properly. And this will be the case no matter how the word is spelled, or even if you try to immediately copy someone saying it the exact way they want you to say it.
> The Haitian languages, French and Haitian Creole, pronounce the r as a uvular approximant or a voiced velar fricative, respectively so their speakers can have difficulty pronouncing the alveolar tap or the alveolar trill of Spanish, the language of the Dominican Republic. Also, only Spanish but not French or Haitian Creole pronounces the j as the voiceless velar fricative. If they could pronounce it the Spanish way the soldiers considered them Dominican and let them live, but if they pronounced it the French or Creole way they considered them Haitian and murdered them.
The last time written Hebrew meaningfully changed was when the Paleo-Hebrew script was exchanged for Aramaic block script 2.5 thousand years ago, but even then, the replacement was 1:1 — ע was still Ayin, it was just written with a different character. And Paleo-Hebrew script has been around since the Bronze Age.
And, importantly, they would not even have realized that they were saying it wrong, because they would have been unable to hear the difference.
As a modern example: I have an acquaintance from Tonga. At some point she got very frustrated with the people around her who didn't understand what she meant by the "rittel bin". She finally pointed at the trash can.
"Oh, the litter bin!"
"That's what I said, the rittel bin!"
In Tongan, l and r are the same phoneme, and native speakers cannot distinguish them without practice.
For all I rib my wife about falling on the other side of that line, it took my American ear a long time to hear UK-dialect(s) distinctions between 'Mary', 'merry', and 'marry', and still a fair bit of concentration to reproduce them!
One I'm struggling with: Norwegian (bokmal at least) has the "y", which is between i and the German ü. I can kinda hear the difference, if I pay close attention and the speaker is deliberate about the pronounciation, but saying it is kinda hard, and I get it wrong most of the time.
It also doesn't help that we much rely on the written word to learn. Which reinforces the reliance on existing symbol-pronunciation associations, instead of creating new ones.
So when a Bengali is reading the verse, what they’ll speak can be basically “they said, ‘Then say “Sibboleth”’, and he said ‘Sibboleth’ because he couldn’t pronounce it properly”.
When the Russian speaking captives tried and failed to utter the [y] they were shot on the spot. Finnish natives got the luxury to starve often to death in concentration camps.
In WW2 the sibboleth was changed to "höyryjyrä".
I recently read Robert Harris's book V2 based on this town. Good book.
Also, there is a chess opening variation named after this place. (see https://en.wikipedia.org/wiki/Sicilian_Defence,_Scheveningen... )
And it has held great chess tournaments in the past.
Plus the Scheveningen system is a method of organizing a chess match between two teams.
For a fairly obscure location, it certainly got on the map, so to speak.
Why do I need to activate mandatory 2FA in services like GitHub repositories for hobby projects? It's a lot of extra effort for a questionable security improvement, and anyway, if someone impersonates me there, it's not the end of the world. If they care about end users (which my projects mostly don't even have) mark me as "unverified" or something, but let me avoid the hassle.
And in more serious services, like banking... since there is no such thing about 100% security (and in particular 2FA is far from it, e.g. if your phone is stolen with the banking app open, you're screwed), actually the most important thing is that the bank responds and can refund the money if fraud is committed, which it inevitably will for some percentage of unlucky customers. I view 2FA as a way to pass responsability to the customer ("we have very secure systems, so if someone transferred $X out of your account it's surely your fault"). Personally, I feel safer with less security and the bank worrying about fraud than the other way around, so I don't think they're protecting me when they implement this kind of stuff.
The only thing that can compete with password managers on user experience is just actually remembering they're logged in instead of pointlessly logging them out every single day for no reason.
Passkeys will be faster.
Seems to me, and I may not understand it, but it seems to me that Passkeys are more of a way to eliminate having to constantly re-enter you password, but do not eliminate passwords.
For example, if I set up a Passkey, that's bound to a specific machine/browser/phones/whatever. But if I log in from another device, there are no Passkeys, so I just need to use my password. If my lose my machine/browser/phone, I'm in the same boat -- new device, and I need to login. Thus the password.
I don't use any syncing system, I'm not on iCloud, or use apps, or anything like that, so there's no mechanic for distribution of passkeys. Plus that wouldn't work if I wanted to log from my friends laptop, or something like that.
Am I mistaken in how this works? How does enabling Passkeys eliminate 2FA?
My issues with 2FA aren't so much the 2FA part (yea, it's a pain in the neck, "one more step", etc., but, it is what it is). My issue is that if my 2FA is lost, and my recovery codes are lost, I'm toast. There's no other way to recover. No other mechanic, at least for Github.
iOS and Android can also just keep local Passkeys where you scan a QR code, though of course if you don't backup anything anywhere you will always have a redundancy problem with any 2FA mechanism.
Passkeys are supposed to not be a single authenticator either, so you can enroll another Phone or a Yubikey (or also your local TPM, binding to your user account, for convenience), but not all services support that in practice.
So, they forced me to use 2FA, and I dutifully printed out the recovery codes (don't write down your passwords, that's bad practice, but here's 20 recovery codes that stand between you and losing your account forever, so you know, manage that somehow).
When I bought a new iPhone, apparently none of my stored information got copied over. The apps did, but none of the information for those apps (for example, the TOTP info maintained by the authenticator I used). So, I went to log in to Github, opened up my authenticator app, and it was blank.
Thankfully I had the codes...back at home, in a drawer, guarded by a cat, so I wasn't completely doomed, but it ruined the day to be sure until I could get home and recover it and recalibrate my TOTP app.
Oh, guess who has a photo of their recovery codes on their phone now?
Also, your Yubikey is probably less likely to be stolen or break, but I figure it's much easier to lose it, which is why you might want to have two, just in case. And that's where it gets really inconvenient.
Half the time I choose for TOTP authentication over Yubikey because "Oh god it's in the living room I don't want to go get it."
I do have a backup key mind, but that's USB-C instead of A. Maybe I should make another USB A backup.
On the other hand, you know the second one works and haven't spontaneously bitrotted.
My nerdy preferred version would have been (pre-passkey) to have a hardware token where the root secret is generated out-of-device and exist on e.g a paper backup or something. Then I could just buy a new hardware token and inject the same token if the device dies.
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
There's then the whole mobile problem -- yubikeys are perhaps fine with my laptop, but how about when I'm using a mobile and my laptop is in my bag, or at home?
And OK, lets say I solve all that. How do I add a second key?
The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons. It also ties in well with my phone -- if I get an SMS with a number 123456, it appears as an automatic insert option on the form, no need to go to another app to copy a number and switch back to paste.
TOTP and Yubikeys do not match the usability of SMS.
Even if I do have keys, they are safe in my pocket, not sticking out the side of a fragile USB port.
It's difficult, though not impossible, to break your USB port with a Yubikey due to its shape. It's not a regular USB plug and will come out quite easily. but how about when I'm using a mobile and my laptop is in my bag, or at home?
USB-C and NFC variants are quite common. And OK, lets say I solve all that. How do I add a second key?
The same way you add the first--most of the time, you have to scan a QR code. You can scan it more than once. The beauty of SMS for 2FA is that my phone number sticks with me. If my phone is lost or stolen, a new sim card is sent to my home and I have access to all my 2FA authenticaitons.
I'm not giving you my phone number, and mobile providers are known to send replacement SIM cards to random strangers if they ask nicely.0: https://apps.apple.com/us/app/2fa-authenticator-2fas/id12177...
I don't fw TOTP now. There are other apps, but I'm done. I'll only use it if the iPhone Keychain has built-in support some day.
When a QR code is present on screen that resolves to a TOTP seed, an additional context menu option should be present to "Add Verification Code in Passwords" or "Set Up Verification Code" or similar.
Here's a screenshot I nabbed from a way-too-wordy article on the subject: https://tidbits.com/uploads/2021/10/Add-Verification-Code-15...
I've done it in Aegis multiple times. They even allow you to export the 'database' (which iirc is just an encrypted json file)
If I ever want to set up a TOTP app on a new device it is not hard to decrypt all my saved QR codes, open them all at the same time in Preview on my Mac, select the option to show one page at a time, and then get into a nice rhythm using one hand to scan on the new device and the other to hit "page down" on the Mac keyboard.
If the site also gives a text form of the shared secret from the QR code I save that too. Having the text form around is handy in case I need to login but for some reason don't have the devices where I have the TOTP apps. Given the text form of the code, this command, from the oathtool package, will give the current login code:
$ oathtool --totp -b "secret"
That's if the secret is encoded in base32, which they commonly are. If it is in hex leave off the -b.If the site doesn't give a text form of the shared secret I read the QR code to get it. If you do that be careful. Some QR code reader apps do the processing server side which you probably don't want...and they don't necessarily make that clear in the description. I had to try a couple of apps from the Mac app store before finding one that did it client side. (Then I found out that Mathematica's BarcodeRecognize function can do it, and deleted the QR code reader app. Now I just open Mathematica, type BarcodeRecognize[], drag and drop an image file that has the QR code between the brackets, and hit shift-return).
Personally, I email the backup codes to myself. Yes it's less secure in theory, but the only time I'm using totp is against my will.
The QR code is on the screen of my desktop Mac. The camera is right above the screen facing me and can't see what is on the screen.
I could read it with the built in camera app on my iPhone or iPad, but that just tells me it is a QR code for the TOTP authenticator app I use and opens that if I tap. I don't see a way to get it to tell me the content of the QR code in text form. Even if it had a way that would be on the phone and I want the text to save it on the Mac.
Because your hobby-project can emerge to be the backbone of someone's multibillion dollar-business, or a small gear in a million other projects, and you will get targeted for a supply-chain-attack.
Forcing everyone to raise their security and gain awareness about those things is a huge win for everyone, and only a little problem for the individual user. And it seems to be only a phase anyway, as most people & services are moving to more comfortable solutions over time.
By the users of the software I publish noticing the license that states that while I hope this software is useful to them, it is provided with `"NO WARRANTY, NOT EVEN FOR FITNESS OF PURPOSE" and planning accordingly.
If you're an entity that wants to ensure that software you use from a source that you have approximately zero power over (and has explicitly provided NO warranty for that software) is and continues to be fit for purpose, you're going to have to inspect that software at a point in time, determine if it is fit for your purposes, and carefully inspect every future version of that software that you're considering using.
There really are no shortcuts. Requiring one to drink a Confirmation Can to log in doesn't change the math here.
Or they can use hobbyist-written software for free, which is just fine, but don’t expect the hobbyist to support it for free.
Fork and change the readme to reflect that this version is hardened for big business.
Turning providing source code into promising you'll follow other's desires on how it should be worked on is a recipe for disaster while simultaneously not really making hobby projects low risk to rely on anyways.
Same reason Microsoft forces Windows updates so aggressively - because if some kind of security breach makes the news, even if it's clearly due to poor user choices (poor password choices and/or security; repeatedly opting out of critical security updates), it's always the vendor/service provider that looks bad.
This way, free users are less likely to use github while paying corporations will stay.
In that case, presumably I could embed the totp key in a bookmarklet in the conveniently-sized 'public bio' field on my profile so I can complete it on whatever device I happen to be using, and effectively opt out?
But I'm really not convinced they aren't fuckwits and wouldn't treat the 'second factor' as an authoritative single factor in some circumstances (e.g. password reset) which wouldn't be unauthenticated if 2fa wasn't set up.
I'm also not convinced one can even contact anyone at GitHub clueful enough to answer that question authoritatively nowadays rather than reading off a script.
2FA increases risk of the account owner losing access to their account. There are a huge amount of posts online from people livid about getting locked out of their account because of some mundane reason like their phone breaking. That risk rarely seems to be considered by the crowd pushing 2FA everywhere and anywhere, probably because it happens most often to non-techies.
Things that seem easy or obvious to folks working in tech are often a huge hurdle for regular users, who make up the majority of users for many products. Many tech companies could do a much better job of considering the needs of their users, rather than building what the devs and product managers personally think is cool.
With my one not really as you still have to enter a simple password to do anything - six letters, no dumb requirements for capitals and odd symbols.
There is something to be said for simple passwords that people can actually remember. They don't work in situations where hackers can try loads of attempts electronically but where you have to type them if they are quite good really.
Not that long time ago there was a discussion about 23andMe data leak through user accounts that reused emails/passwords on some other compromised site. I was surprised how many people here argued that 23andMe should be responsible for this data breach because it's common knowledge that people reuse passwords all the time and yet 23ndMe didn't make 2FA mandatory until after the leak.
Personally I prefer to have a choice on whether 2FA should be enabled or not but I also understand companies that don't want to be blamed for something that is entirely user's fault so it's much easier for them to make 2FA mandatory, even though with phone apps it's not really 2FA since it's the same device.
Instead they just mention it in passing with a "only time will tell" comment
By the title, I thought the article would explore some of the downsides of this approach that I might be missing.
Biometrics are a convenience feature, not a security feature.
Fingerprints are trivial to lift and replicate. Face unlocks can be fooled by pictures, or in some cases, get false positives from people that just look enough like you (which is common in some Asian countries). Even if it requires you to blink, new AI tools will easily generate a video of you looking around and blinking.
But the worst part about it all, is that biometrics are a password you can't change without surgery.
I really REALLY wish "biometrics" would stop coming up as a solution to security.
Reminder that the outputs of AI don't reflect some deeper truth about reality, just an extrapolation of the training data. Garbage in, garbage out.
I think this should be “more similar than other groups” rather than simply “similar”. Even then I think it’s possible that some groups have more loci with higher diversity for facial features. That’s not even getting to epigenetic and environmental elements.
I think the deeper truth is in your final paragraph: facial similarity is in the eye of the beholder.
Like with many things pertaining to security, there are no universal solutions without first defining the problem.
Say for instance, you have an access control system where you want to solve the issue of credentials being intentionally shared. Biometrics are a great solution for this; tokens and passphrases are not. You need different tools for different problems.
i can't go up to just any computer and log into my bank with my face
you would have to possess my phone and then deepfake me
i am comfortable with this security posture because the convenience of face id allows me to use long random passwords with frequent rollover which I never have to type
if i lose my phone I can remotely disable it
this is all much less of a crime to me than any service that allows password reset over SMS which is a much more well trodden vulnerability.
Isn't that only Android (and maybe only older models)? Doesn't iOS use a LIDAR sensor instead of the camera?
On Windows for example you can't even have face unlock without a sensor that will provide 3D details so most laptops don't support Windows Hello.
I recently argued, as the cybersecurity guy™, with a vendor that we can't ask regular users to reauthenticate every 15 minutes. They insisted raising it would be to insecure and instead suggested to make MFA optional as it would make the login process smoother…
[0]: https://auth0.com/blog/balance-user-experience-and-security-...
That type of thing seems ideally suited to healthcare use, and we have such better devices now than whatever cards were used way back then. Amazing it's still Windows PCs deployed and secured with passwords.
What's even the attack scenario? Someone stealing a session token/cookie? If they can steal an expired one somehow, then there are good odds they could steal a current one, so the short session doesn't matter THAT much. I suppose another scenario is someone not logging out of their accounts on a public computer, but the type of person to do that likely uses "Password123!" as a password anyways.
What is insane is that so many services allows to reset password and even 2FA without requiring any cooldown. The level of fail here is plain staggering. I don't really have words.
There are proper services out there who shall go out of their way to try to contact you, for example for 72 hours, before allowing any reset to happen. Some are going to say: "Wait, what!?, 72 hours!? I need to reset my 2FA NOW". They don't realize though that what they're really saying is: "I want bad guys to be able to reset my password/2FA instantly and log me out of everything they can in a split second". It's convenience vs security, once again.
As a sidenote I've read about a DB (in the EU) about SIM cards saying when they were swapped. And as a bank, you can check that DB and decide, for example, to refuse to let anyone change any setting if the SIM was swapped less than a week ago.
We need more people to think a bit about potential solutions instead of crying "but it's not convenient" and "bad guys shall find a way anyway".
If it's expiring in a few minutes, presumably you're trying to protect against two things: (1) Session hijacking and (2) Unlocked computer.
Session hijacking is somewhat preventable via other means (eg: IP address tracking), but more importantly, in what case can a session be hijacked only 15 minutes later?
Someone walking away from an unlocked computer is an impossible problem for a app/site to solve. If an attacker has access to the PC, they can install malware that sniffs all traffic or passwords, and if the user saves their password(s) on their PC all of those are compromised anyway. This is a responsibility of the person responsible for the computer -- eg, the user and/or the IT admin.
When sessions/passwords expire in a time measured in days, I can't help but think they are basically saying "it's okay for an attacker to have access to this system for 89 days... but not 90!" The only valid argument I've ever heard for this is an attacker might be doing offline cracks of passwords -- but there's so many other fails involved there that I can't see how blindly expiring them is at all useful by comparison. Not to mention rotated passwords are very predictable[1] so it's unlikely to even mitigate the attack.
[1] https://www.sans.org/blog/the-debate-around-password-rotatio...
For my service I ended up doing something in between. Sessions last for 14 days, but they are automatically renewed indefinitely. So as long as you access the service every 14 days your session will never expire. This way lost or leaked credentials aren't a risk forever. But in most cases users rarely if ever need to log in again. I may play with the exact timeframes, or maybe significantly extend the validity if the user is logged in via the same IP or similar heuristics. But I like that after some definite period old creds are no longer live.
> someone just threw out an old PC that they haven't used in years and the disk isn't encrypted.
These are scenarios where I think expiration doesn't help at all. I assume your reaction is not just "oh well, the compromised sessions on that device will expire in 70-ish days so we can just ignore it" but instead you immediately consider everything on the device compromised and kill all sessions, rotate all account passwords, etc.
If it takes you a day or two to notice this event happened, expiration doesn't help: long expiration hasn't happened yet, and with a short expiration, you still don't know and can't assume it protected anything. In fact, the safe thing is to assume the session was accessed within minutes of the incident.
> For my service I ended up doing something in between. Sessions last for 14 days, but they are automatically renewed indefinitely.
This is a pretty rational approach, but of course the time frame depends on your users and how they user your system. Auth0 has a good rationale behind their approach[1]:
> You can configure session limits with up to 100 days of inactivity (idle timeout) and up to one year in total duration (absolute timeout).
> The motivation behind the 100-day idle timeout cap is to cover one quarter plus a few days, which provides wiggle room for people who log in to do end-of-quarter reports.
[1] https://auth0.com/blog/balance-user-experience-and-security-...
https://pages.nist.gov/800-63-3-Implementation-Resources/63B...
While I understand the burden on organizations to protect user data, the user should have say as well. A one-size fits all solution almost always leaves users on the lower slopes of the bell curve vulnerable or frustrated.
And even if you can get in-person with someone, the new "secure" systems may block them from being able to help, anyway.
But the title seems like pure click bait, as the author didn't spend more than 2 sentences on passkeys/Webauthn (which is the typical tech for passwordless solutions nowadays).
I have my own issues with Webauthn usability and was expecting a deeper dive into that.
That larger problem, of course, is that security and ease of use are in tension. Always were, always will be.
* unlock your phone * tap notion * you're logged out - avoid the big login with x sso buttons, scan for and click the little text that's black on black labeled "login here with email" * type my email out (no autofill) * tap submit * exit app, open mail * find the notion email, usually it's right there other times, you must refresh constantly, sometimes it takes whole minutes because it's email * highlight as much of the password as you are able but not all of it because you can't due to the dashes * adjust highlighted text while holding down long enough to pop up the copy context window or memorize a cute phrase with dashes and type it out without making a mistake, 3 taps a dash (x4) because mobile keyboard layering * hit copy, exit app, open notion * press and hold in the textbox for the paste window or type it out * finally hit paste and submit * remember what you were trying to do quickly
Now add slow or glitchy(5g+) internet and it doesn’t work.
Even if you wanted to tie yourself permanently to an sso provider, a lot of the time, they too require re auth. If you have 2fa on (as you should) that's as many steps. The push for sso is also incredibly annoying. I’ve nearly deplatformed very intentionally.
Notion does a lot of funky things like refuse to build and offline mode which exacerbates this.
One other thing I don’t like about “passwordless” is biometric as a security feature instead of it as a convenience. 1Password removed passcode unlock on mobile in favor of faceid. Which if you don’t use it results in entering your full long password every time you use it, even if you just used it. Apparently I wasn’t the only one that complained because they restored the feature shortly after removing it. I unlock my friends phones while they are driving with faceid all the time. Too easy, not secure enough for the app that has most of my secrets.
Use 2fa, local passcodes that require reauth occasionally, and assume you are running on a locked device, if logging in from a new place maybe 3fa like Coinbase.
I do NOT want to have to sign in a billion times a day, even if it's relatively quickly with FaceID or similar.
Today we use passwords largely for personal security. Yet when companies choose what methods of authentication/authorization they offer, they don't care what the user wants. They pick methods that will make their own jobs easier, rather than giving the user more convenience. The user has no agency today; it's just take what they give you and be thankful for it.
As a result, the tech landscape is full of wildly varying authn+z methods. Inconsistent password policies, inconsistent challenge methods (when they exist), inconsistent use (and types) of MFA, inconsistent use of hacker-prevention methods, the occasional use of single sign-on for only a few identity providers, "magic login email links", nearly non-existent use of client-side keys, etc etc. Almost every site you login to today will have a different system. Passkeys aren't much better, because it too is just a hodge-podge of different standards, not all of which need to be supported.
We need more consistency for the methods that exist. There should be a standard for challenge questions, a standard for hacker-detection, a standard for password policies, a standard for MFA, etc. That way it will be a little less haphazard how everyone implements them, and it will be easier to prevent security bugs by following the guidelines for implementing the standard.
But I also think more should be done to advocate for what the user wants. If the user wants to use a regular password, let them enable it. If the user wants to disable MFA, let them disable it. If they want to opt-out of the multi-layered hacker-detecting challenge-questions, let them opt-out. This is, after all, their personal security, not the security of the entire company selling them some service or product. A person should be able to decide their personal security level.
Alas, we don't really have much choice in what current companies give us. But if we voice our opinions loud enough, maybe new companies will give us the agency we want, and maybe that tiny competitive edge will prompt other companies to match them.
So we need more standards. But those standards need to come in three varieties: 1) new standards, 2) simpler designs, 3) guidelines for implementations. There are solutions that exist today, that have no standard. There are "standard" designs today, but they're overcomplicated. And we need better guides on how to implement standards so that users (and developers) have an easier time using the solutions.
I'm a little disappointed that it didn't talk about passwordless logins, at all, though. I'm thinking of implementing one, and I was hoping this would give me some food for thought! Ah well.
With 2FA, a lot of times I’m going to go through endless technical support, or I will be told it’s simply “not possible” for me to regain access to my accounts.
There’s a third tier here, which is 2FA at work. If I lose a 2FA token I can usually get the IT or security team to let me back into the system because they’re physically present and know who I am.
So "not copyable" is actually a huge downside for convenience. Such a downside that even though I have a collection of U2F keys I only use them in a handful of accounts. The maintenance cost is just far too high.
To resolve this you would probably need something like cross-signing. So I can say "I know that you only trust key A, but I lost it a few years ago. However I have an attestation from key A saying that key B is mine as well. Here is a signature from key B". However this is effectively equivalent to copying keys. So it basically defeats that point.
[1] https://support.yubico.com/hc/en-us/articles/360016649339-Yu...
I thought it would have more depth though into the current state of various authentication schemes, in particular passwordless, which isn't actually mentioned at all. I find passwordless to be slightly less bumpy than various 2FA but still a genuine pain in the ass, to have to open up email in a second tab, wait for the email to come through, and then often follow a dubious link.
This, and also brand dependency, is what makes my worried about passkeys. If I got the idea correctly. It hashes my fingerprint data, but what if my fingerprint changes? I have that very often on my iPad that it stops seeing my thumbs as the correct thing. I assume that happens due to some manual work I may do. And my thumb becomes different to the sensor. I hack that with my pinky finger, for some reason it’s more reliable. But what if something happens to the sensor and it stops being reliable.
What are my options then? What are my options if I’m about to change my smartphone brand? What are my options if I’m on my PC that has no sensors for any biometrics?
When you say passwordless in this day and age my thoughts go straight to hw keys.
And speaking of hw keys I started using one alongside my gpg password for my personal password manager a year ago.
After 1 year I removed the hw key from the list of keys.
My experience is that it's more of a hassle to reach for a hw key every time I need to view a password, than it is to just enter a very long passphrase.
I'm of course special to be able to remember multiple very long passphrases, but as long as I do it's much more convenient.
Then it also got me thinking, what if I had gone 100% hw key and lost the key? Then my passwords are lost forever. It's much harder to lose the passphrase in my head.
A friend of mine recently got caught in a loop where he wanted to interact with an account that he hadn't used in a long time, which was registered under an email he hadn't used in a long time, which had a recovery email set which he also hadn't used in a long time. He had the passwords written down for all three, but account A refused to let him in without an email verification (but would let him in without a password, if only he could access the email), and email A wouldn't let him in without proving he had access to email B, which wouldn't let him in without proving he had access to email A. A person who wandered into a logged-in computer with access to email B could theoretically have done anything they wanted to all 3 accounts, password or not, but the rightful owner was forbidden from using any of them, despite knowing all the passwords.
I miss the days of, "You have a password, and we'll assume anyone with that password is you. Don't get phished." It's actually pretty easy not to get phished, and sometimes downright impossible to go through the hoops that all of these new anti-phishing measures require.
A service I stumbled into recently which I think does it right is Mullvad. They've taken it a step further and done away with usernames, too. They just give you a long numerical code and tell you that if you lose it, you're screwed. It feels much more respectful to the user.
Trusting 743 “randos on the internet” to safeguard “my” data, and give me access to use it.
Insanity.
Agent-Centric systems where I retain signing keys to authorize access to (and transactions using my) data are the way forward.
A Key Fob (like you have for your car) is not onerous, and methods for recovery using trusted community members is practical.
Holochain (and the Holo project) are good examples of working implementations.
- Addresses that are wrong
- Passwords stored (probably insecurely)
- Other personal data that can be stolen
If they "need it", they can be granted access to it (or a personally encrypted copy of it unique to them). Of course they can (and likely will) mis-manage even this data; Zero-Knowledge Proofs and Homomorphic Encryption should be used instead, where possible.
Remember, Public data written by an Agent are written to the DHT and are persistenly available, so "upload and decrypt" isn't really usually a thing in Holochain hApps.
So, if they want to make some non-repudiable claim under the auspices of "my account" (ie. claim agency on my behalf over some change of state, such as a "post" under my name, ...), then they can bloody well get me to sign such a state change with my private key. And, make all such data publicly available so that I (by my sole decision) can cease to use their service and take my data elsewhere.
Remember -- these are "randos on the internet" holding your data. Hundreds, or possibly even thousands of them including all the partners they sell your harvested data to, who are evidently incompetent in managing/securing it, and certainly don't care a whit about you and the sanctity of your data.
In other words, agent-device-based identity is a crappy experience for some mixture of end-users and/or devs. Either the user has to manage muiltiple identities, or the devs have to build an ad-hoc identity systems on top of the agent-device-based system.
I think PGP got about halfway there, but falls short in a lot of ways.
In Holochain, a standard service named "DeepKey" (https://github.com/holochain/deepkey, still under development) is tasked with managing groups of "Agent" keys.
On creation of a new Holochain Agent (associated with some Holochain application or piece of hardware), you'll associate it with your Deepkey keyset. Later, you can discard (or recover agency over a lost private key for) an Agent ID.
But at no time should "randos on the internet" be responsible for the agency of your data. That's just crazy -- no matter how "easy" they make it, they simply don't care (evidence would suggest) as much as I do about my data.
This doesn’t work for the internet because anyone can access the target from anywhere.
We already do this to a degree with trusted CA centralization and there are recorded incidents (pretty frequently) of major breaches and state actors posing as various entities.
The stakes are also different, stealing a car is hard to do when it has physical security and has physical consequences. It’s also not worth a whole lot after because it’s hot. Stealing somebody’s identity is worth a whole lot more, hard to if even possible recover from and can be done remotely from anywhere.
I think centralization around brokers is a terrible idea. Look at Equifax, the audit after revealed it was only a matter of time before somebody utilized the multiple gaping completely negligent holes they had. The resulting fine for leaking every man, woman, and child’s ssn, birthdate, address, and drivers license was the equivalent of a few dollars to them.
For some, you might allow "what you know" security (ie. the agent knows your private key).
For other, you might demand "what you know + what you have" security (ie. the agent knows your private key and has provable access to your device). I used various proof of knowledge constructs, such as the ability to read "Private" Holochain entry data (that only exist on-device, and not in the DHT), and demonstrate this by providing the hash or PKI signature of the private data (which is published to the DHT, in an entry provably before the private data being proven was written). There are other ways.
For yet others, you might want that, plus "who you know" security, in which case we do all of the above, and ask some previously defined Agents to also sign the transaction before it is allowed to be written to the Agent's source-chain.
So, the requirement for logical, physical or relational levels of security are available to Holochain / Holo hApps. This is higher security than is available for physical devices like cars, and is even better than provided by devices like Apple iPhone and Watch -- because you retain control over releasing the lock (if you forget your password and lose access to your email address, your Apple device is locked, forever).
I use bitwarden, it has my passwords and my TOTP codes in there, I have this on my phone and on my computers, everything auto fills. Other than that, I also have a hardware key for some services, all I need to do is click the hardware key when prompted. Some services only have email 2FA, but that's quite easy as well, I just get a notification and copy the code from there.
Doing a chain of 3 2FAs for 3 different services takes seconds.
For improved security this is easy, I'm not sure what everyone is on about.
Is this another case of complaining just for the sake of it?
Nor does anyone say what version of bluetooth is required
Isn't putting your private keys on the internet the thing we're trying to avoid?
Source: I work in ecommerce.
Lo and behold, it uses 2FA. Periodically I have to go get my phone[1] just to do my work. Way more friction than typing in the password.
[1] No, I don't keep my phone on me all the time. It usually just sits in some random room at home.
The starred-out password field plus my blank keycaps are a real test of my touch-typing ability.
Some are literally so bad I just won't use them anymore.
All most of these things need is basic authentication, set some long-lived whatever it is based on the Secure Enclave, and if then don't allow seeing the charge method or changing the delivery address without requiring some second factor. You don't need full bank-level security for a burrito (amusingly enough, my bank security is more based on normal things than the burritos are).
for me its about lowering the price to use a service. (as in mental price not dollar value)
I got my whole family Yubikeys a while back, and it seems to be going pretty well.
With standard 2FA, I have backup devices and codes that I can start restart from scratch if my phone is ever lost/stolen/broken.
I never worried about losing access to it.
Until the day I enabled 2FA on it.
You can't get my personal e-mail password out of my mind but you can get my smart phone out of my hand.
I've used half my backup codes by now.
It binds the biologic to the transaction, no plausible denieability.
Great for securely buying Pizza but not so much for the future of humanity.
Citation needed.
Generations before mine talk about their childhood as a wonderful time. Not having to lock their bikes up when going into a shop. Not having security cameras watching their every move. Not having barriers everywhere to prevent theft. My local supermarket introduced receipt scanners a few months ago that block you from exiting. They treat you as a thief by default.
I wish I could live in a high trust society. It sounds like in some parts of world (Japan for example) there are still elements of that.
Steal? Life in jail.
Litter? Year long sentence.
Assault? Life in jail.
Criminals are going to commit crime and there is absolutely no evidence that rehabilitation works for those kinds of crime. We need to keep them away from society and change our culture to be entirely intolerant of crime.
More importantly though, generations past also often lived in smaller communities then we have today. When your world is smaller and you are only a degree or two of separation away from everyone, people often feel more bound to a certain standard of behavior. Stealing a bike in NYC today is one thing, stealing a bike in a town where you probably know whose bike it is and someone will recognize it if you ever actually ride it is very different.
The larger we grow societal centers and the more we expand the boundaries of our own world, the more we break societal bonds and need laws to enforce rules that are more easily broken when your victim is just another random person living there.
I'm rather baffled how educated adult human beings keep on analyzing the world using moralistic fairytale level concepts like "bad actors" or "evildoers" as if there are some inherently tainted souls doing bad things just because they are bad.
In my, probably biased, assesment this is especially prevalent in the US public discourse.
People don't steal cars and bikes to buy food, they do it because they're selfish and want a shortcut to get the things they want. In any first world country there are ways to get food without resorting to taking other peoples' possessions that they worked hard for.
There are many people out there having a really hard time who would never even think about stealing because they were raised with a functioning moral compass.
Theft has the highest recidivism rate too[1]. You can never trust someone who has stolen again, thieves are the scum of the earth and only hurt good people.
[1] https://www.gov.uk/government/statistics/proven-reoffending-...
Sure, we should punish crime but never solving the root problem and taking a "hardline" approach towards the symptoms feels good. But, it puts us in a perpetual state of law enforcement and anxiety about crime.
Agencies like the DEA should be abolished and possession/use of drugs should not equal prison time or anything on your record. Of course, things like driving impaired are still punished because you're endangering others.
College should not be expensive or put you into debt for decades. In the US, we need a general cultural shift away from hyper individualism and unregulated capitalism.
Sweden's welfare state is a left wing dream come true, however the bad news for the left is that it empirically disproves every left wing idea about crime and society.
In a free market, all transactions are voluntary. "Selfishness" just means that you only agree to a transaction if it benefits you. But the other party will only agree if it benefits them, so it's a win-win.
Thievery, OTOH, is not voluntary for the victim, and is, at best, a win-lose. Not at all the same as a free market transaction.
I agree with the OP - as a society, we should look more at aligning incentives rather than instilling morals.
Another huge area this comes up is the war on drugs - if you're caught with drugs, we slap you with a felony that ensures you can't get a real job... pushing you right back to drugs.
I could say the same thing for any sort of crime. If you're an accountant, and you get put in jail for embezzling, that conviction is going to prevent you from getting another job as an accountant.
While there have been a few controversies about jobs that the law excludes felons from, in a lot of cases there's nothing preventing you from hiring a felony drug criminal. If you personally are fine with drugs and you think that committing the crime doesn't make him a danger to your business, go ahead and hire him. If you won't, it isn't the conviction that's keeping him from being hired, it's the crime; the conviction just lets you know that he committed a crime.
If I'm understanding you correctly, you're arguing that a drug user is less employable (perhaps because you believe drug users are untrustworthy or unreliable), and this is the reason they aren't hired.
But a conviction for a drug crime years ago does not mean someone is a drug user today. It is the conviction, not drug use, keeping them from being hired. A drug test would make more sense if you want to determine whether someone is a current drug user.
And besides, without the conviction you may be unaware of their drug use. If someone has a drug habit, but nobody can tell, what exactly is the problem? There are plenty of "functioning alcoholics" in the workforce.
It has been my anecdotal observation that it is more common for small, local businesses to "look past" prior convictions when hiring and be more willing to take chances on their neighbors.
Large corporations with big HR and legal departments typically have a dimmer view of things however.
Right or wrong, it is harder to get a job with a past conviction. Without a job, it is difficult to earn a living, feed and house yourself and your family. When people are desperate and unable to survive through legal means, they resort to whatever it takes to survival. It's human nature.
The educated middle class can afford to hold the most out of touch abstract theories because they don’t need to suffer the consequences.
You can justify some thievery due to social problems - stealing for food is one thing.
But if you eliminate "fairytale concepts" like "bad actors", how do you explain the people constantly attacking managed services and trying to gain access to other people's accounts? These surely aren't the guy on the street looking for their next meal.
As time goes on I believe this less and less. I don't even think it's supported by the data. Spain or Sweden have way more thefts per capita than, say, Poland. Am I to believe a poor person is better of in Poland than in Spain or Sweden? They literally freeze to death sometimes.
I'm Spanish, I remember visiting Helsinki and finding toys in a wooden trunk in a small park for children. My first thought was "How is nobody stealing these?" and the second, immediate thought was how utterly sad the first one was. Am I to believe it's poverty pushing people to steal children's toys?
I think social cohesion is a factor often ignored, which is amazing in a way because it gets alluded to all the time, "They are tourists, who cares?", "Yeah but that guy is rich", "it's a supermarket", "They have insurance", "they are non-gypsies". Any of these has an implied "I don't care about that person because...". And this generates a feedback loop. It's harder to care about other people and have sympathy for them when you don't trust anyone not to steal your stuff if you leave it unattended for five minutes.
In retrospect, I do think those toys got "stolen" frequently, just because children grab stuff all the time and I'm sure it ended up lost more than once, but there must be an insistence to trust your fellow man, to trust that if a good is lost there must be a good reason. I don't think we have that trust anymore.
We aren't some master race with pure souls. Finland was a shithole until about after WW2 after which the society was deliberately built to not be a shithole.
When I generate random passwords, people complain that they're unreadable. When I ask them why the password they need to enter once every two years would need to be readable, they just shrug. When I bring up the ability to save passwords to their devices using a password manager or their browser, they say they're "not into IT" and ignore any advice beyond that. Then they change their passwords to Welcome2024!, and that's why we have to make things more complicated. I don't care about most random accounts, but the Welcom2024! people are the ones safeguarding personal data, medical information, and so much more, and if they don't care, you have to force them to use computers responsibly.
Most websites would be perfectly fine with just a username and a randomly generated password. Even eBay or banks, if we're talking about <€100 worth of transactions/day. 2FA is a workaround only very few, very important services should actually need.
However, in real life, we can't do that, because when the Welcome2024! people get their accounts taken over, their digital wallets drained, their credit cards emptied out, and their life ruined by people on another continent, it's always the websites' fault. People love to say "Google/eBay/PayPal/my bank should've prevented this" but when these services take steps to prevent that stuff, they get mad that everything gets so complicated.
Bad actors will always cause things to be worse, but the general apathy the general public has to digital safety is the reason why it's _this_ bad.
Because no one has ever hacked 2fa and stolen a pin before /s
Which breech will likely be due to an Admin whoopsie of some sort.
Because the people remain the weakest link.
Heh.
I see that this skepticism has offended.