Password reuse is rampant: nearly half of observed user logins are compromised
blog.cloudflare.com
blog.cloudflare.com
For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.
I've broken any biometrics recognising me in a dozen different ways, this year alone. Cut open my finger, changing my fingerprint. Head surgery for melanoma gave me a scar so facial recognition doesn't work anymore, blood vessel burst in my eye, so iris scan changed. And so on.
They're fine for a convenience, but that's it. They're nothing more than a pin, and you will have to fall back to password or authenticator or something else, sooner or later.
For remote authentication you use a private key accessed via the local system (which you are already authenticated to using biometrics).
That does not imply a pin or password for easy fallback. That implies something harder, that os self-destructive on use.
[0] https://www.abc.net.au/news/science/2023-11-01/ai-facial-rec...
With 99.99% chance you forget it before you ever get to enter it because humans forget things they never use :)
It'd be much easier for porn & social media ID laws to be enforced. Which could be abused by adtech and law enforcement.
I don't want a key limited to a single device I just want a strong key that can automatically login to a website. The technology has existed for longer than the internet it just needs to become the norm.
Also, you don’t need to remember only the base password and the rule. You also need to have an exceptions process for when your “generated” password is incompatible with the esoteric requirements of a new site (length, character restrictions, etc.). And you need to remember this at login time, when you aren’t presented with the same information about those requirements as you were when you registered.
Much easier to just manage randomized passwords through 1Password.
Maybe someone should investigate how many sites require a password but really shouldn't.
People don't realise CloudFlare is a MitM-as-a-Service.
We've worked on this stuff for years (this stuff being how to warn users about compromised passwords). You can go back to 2018 with our work with Troy Hunt on Pwned Passwords (https://blog.cloudflare.com/validating-leaked-passwords-with...), or our 2021 work on a privacy-preserving way of checking a password against a list of known compromised passwords (https://blog.cloudflare.com/privacy-preserving-compromised-c...).
Try implementing what CloudFlare does yourself. You will very quickly realise how it works. It's actually pretty crazy.
A HTTP post request along the wire is unencrypted.
I'm talking about a submit button not HTTPS as that just encrypts the connection session and not the data sent from say a form.
If you're using or utilising CF for something where the data is being posted to an API unless you have client side encryption anything receiving that data will be received in plain text.
Someone only needs to compromise the service worker and syphon the data.
The data from the form, HTTPS POST data is not encrypted. It's plain text encapsulated in a secure socket.
Setup a PHP page with a form and capture the $_POST. All will return in plaintext.
POST is data is sent in headers which yes are encrypted by SSL but the servers receiving will receive it in plain text.
By using third party you lose full control of the data flow encrypted or not. All it takes is one weak link in the chain and your data is screwed.
You're relying on the 3rd party infrastructure not being exploited.
If CloudFlare, any "relay" were compromised, all traffic through that would be compromised. That's everything. All your bank details, full access, it's all right there.
The selling point of SSL is nobody can read what you do between you and the final destination, except when the developers of that destination enlist CloudFlare who have a root certificate that allows them to intercept everything whether you realise or not.