Precisely. So much added expense for zero, or rather negative, added value.
Precisely. So much added expense for zero, or rather negative, added value.
Proving Netflix could be replaced by five hard working people.
Bragging about not helping others isn’t the flex you think it is. :(
deleted by creator
ircCloud because my self hosted push notifications were failing and it worked right away.
Irssi before I started depending on push notifications though.
What makes it more of a minefield than email?
You’re using the word ‘stolen’ which doesn’t fit. It would be accurate to say 'every answer comes from possibly unlicensed material '.
++ Totally. 10€ a month can’t be close to the value of the data. If the cost was actually based on the value of the data it might be a valid choice.
I’m still curious where coercion comes into it?
You choose to visit Facebook. They’ve always provided services funded by your data. Now you get to choose between that model or compensating them directly.
Where does the coercion come in?
PS, I hate Facebook and don’t use it in case that matters somehow.
Wait… you would get behind ruining Wikipedia just so you wouldn’t have to see fundraising banners when you use it?
Thanks for the civil discussion. While my views haven’t changed I have learned a lot about possible objections from informed people.
Let’s hope this new auth standard is implemented responsibly by all the major parties and that weak passwords and phishing become relics of the past.
But that’s the whole thing we are trying to solve here. We are trying to eliminate human factor and by extension bad habits people have when it comes to security. So expecting people to use good passwords and pins for keys will be the same as expecting people to have good passwords for accounts. Perhaps even worse because of claims it’s better security so people might even relax more.
I feel like it’s 2001 and I’m trying to convince my users to switch from passwords to RSA keys for SSH. Yes there are potential weaknesses. Yes it’s still much better.
Also timeouts with pins and passwords mean very little once someone has your device. This is why I don’t consider it good two-factor. PIN might be in your head, but nothing is preventing someone brute forcing it. Once you image the device you can do whatever you want. With credit cards, you’d need ATM to keep doing it and lockout is a serious problem there.
Even if all we’ve done is reduced potential attackers from everyone with an Internet connection to people with physical access to the device we’ve still massively increased the average user’s security. And we’ve done more than that.
Also unless you can clone the device somehow hitting max guesses and losing access just like an ATM is part of the design.
It’s a step in right direction for sure, but I’d prefer if keys didn’t depend on PIN or password.
I lost track of your suggestion over the weekend but what was your suggestion for second factor other than a pin or password?
Kinda. Given that nobody else supported it Google dropping it did sort of kill it. Passkeys are very different as they are already supported by Apple, Microsoft, and scads of smaller companies.
True. In the context of this thread it doesn’t matter though.
You link to articles about law enforcement hacking phones to get data as a reason not to use biometrics? If they are hacking your device it doesn’t matter if you use a password or a fingerprint.
Use a pair of hardware tokens and a long pin if you want maximum security. If you want to use a sync-able software token do that and set a strong pin.
You like long passwords? Go ahead and put one on your passkeys. You don’t have to use a short pin.
It is two factor. Something you have, key in TPM or hardware token, and something you know: the PIN. Or if you choose to enable biometric it shifts to two things you have the: key and your face/fingerprint.
Remember you only have limited attempts to guess the PIN and biometric auth is subject to configurable timeout conditions before the PIN is required.
Any security conscious person will use a strong PIN. Many will choose to use biometrics as well for convenience. Most people are still setting their password to Sm3llyK@t42 on every website. A protected key and a 4-digit pin/finger print is a huge leap in security.
What do you mean? Do you not believe the anti-phishing features will work as described for a reason?
Then you have a nice juicy lawsuit. No legal protection is going to prevent a rogue cop from getting your data. https://xkcd.com/538/
Now do the A spec.