5 ms·
That's an option for some people, not an option for everyone.
by sarciszewski 11y ago
That's an option for some people, not an option for everyone.
- WorldMaker 11y agoThat's the conversation I think we need to have as a developer community. Why isn't it an option? Why isn't something like Passwordless the new default? From a security standpoint it has no worse a security stance than existing password systems: you have to have a one-time token based Forgot Password system. Humans are extremely fallible at storing passwords and in 2016 it's considered unacceptable a UX to not include a "Forgot Password" button. From that stance, Passwordless is simply "Forgot Password"-only login. In 2016 if you have a password system and a "Forgot Password" system, I guarantee you already have "Forgot Password"-only users. With modern lockouts and password requirements, we've essentially trained entire subsets of (even not-so-forgetful) users to click on "Forgot Password" before even bothering to attempt a password. "Forgot Password" is already, de facto, the "one true login button" on the web. Are we doomed to this miserable UX flow for eternity, simply because it's now the entrenched platform default?
- creshal 11y ago> Why isn't something like Passwordless the new default? Because we had a dozen "the end to all passwords" schemes pop up over the years and they all lost steam and died and were replaced by the next shiny thing (this time the really ultimate!) before any user managed to use them on more than two or three sites, at most. Despite everything, passwords have one advantage: They work, and they will keep working for the next ten years, and not just until the next fad. (In its defence, Passwordless does seem pretty reasonable and decent. But so seemed others.)
- WorldMaker 11y agoPasswordless isn't so much a scheme as a simple quest to revisit basic UX assumptions: why have both passwords and a "Forgot Password" button when you can drop the passwords and only have the "Forgot Password" button? Maybe there will be something new and shiny that will come later, but likely it wouldn't be a replacement to Passwordless, it would be an augmentation or a expansion to it, because really it doesn't get much more simple than what Passwordless is encouraging. The problem is that passwords don't have any advantages and aren't working. They aren't working for us as devs (see the article this is attached to), as password data security gets increasingly harder every year in a war of attrition with black hats we maybe cannot even win, and they aren't working for our users. Users don't remember passwords and they don't want to remember passwords and they have so many passwords they possibly need to remember that they aren't going to even try to remember passwords these days. Power users rely on password managers (and don't even know their passwords; removing it as a "something you know" factor and moving it to "something you have" weakening any supposed 2FA) and average users use the weakest passwords they can get away with and/or already rely almost exclusively on your "Forgot Password" button (or sometimes worse, your "New User" button). It's 2016: passwords aren't working. They haven't worked well for us in years on the web. (Citation: the bundle of new "Please reset your password because we were {breached, forgetful and stored our passwords wrong, found your password in someone else's breach, expecting a breach}..." emails every year that are becoming the new normal.) Passwordless maybe isn't the long term solution, but it's a better default security stance than our existing preponderance of databases storing some variation of large lists of hashed passwords, and its about starting with not lying to ourselves that we are more secure than we actually are. More often than not, passwords are security theater these days and it's time we did something about it. I'd love something more secure and capable than Passwordless (a wish for a distributed federation system that worked and passed mainstream scrutiny and acceptance), but I'd settle for something like the Passwordless approach as a near term solution.
- SAI_Peregrinus 11y agoPasswords (or passphrases) are really the only way to securely verify the "something only you know" factor of authentication. Alternatives either devolve to storing a password somewhere else (password safes, passwordless, etc) or to "something only you have" (tokens, smart cards, biometrics). It's easily arguable that the "something only you have" factor should be the primary factor, especially for low security systems, with "something only you know" being the secondary factor for high-security systems, but the economics have tended to reverse the situation. It's a lot cheaper to ask a user to memorize a password than to get smart cards or fingerprint scanners for everyone.
- trowawee 11y agoAlso, it's really easy to reset a text string and rather difficult to reset a fingerprint.
- WorldMaker 11y agoThe Passwordless approach falls under "something only you have", and does make that the primary approach: tying your login security to your possession (lease) of your email address. Uses the same one-time token system that a Forgot Password or a "Verify Your Email Address" approach uses.