5 ms·
One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time.
by vit05 9y ago
One thing that I have always thought about is why Emails doesn't have disposable passwords. For example, you make 1 new password that you can use just one time.
That way if you need to use unsafe PC from a hostel, you can log in with that password.
- jlgaddis 9y ago2FA
- jscott313 9y agoBackup codes are exactly that, though they're more in case you don't have access to your 2FA device.
- eggnet 9y agoYou're basically describing two factor authentication, when you have not authorized the particular computing device in question to skip it.
- robbyking 9y agoOr why we have passwords at all. Sites like Medium have moved to a passwordless model, where you're sent a login link to access your account rather than forcing you to remember or retrieve a password. https://blog.medium.com/signing-in-to-medium-by-email-aacc21134fcd https://blog.medium.com/signing-in-to-medium-by-email-aacc21...
- pavel_lishin 9y agoWhere would you send a link to log into your email?
- c0wb0yc0d3r 9y agoI was thinking it would be super cool if you could use something like https://krypt.co/ https://krypt.co/ and use public key private key. Sure, you would need that ssh daemon running on the computer, but I bet it could it could be retrofitted to use qr codes or something.
- urda 9y ago... so a link sent over a protocol that is considered "insecure" by any sane security expert allows account access? Not to mention you still have to "secure" a password to your e-mail account. I'm sorry, what in the world is Medium thinking? This is a step backwards from a user/password model.
- robbyking 9y agoThey cover this in the article: "reset my password" emails are already the norm, so it's not any riskier than your existing online banking or social media accounts.
- urda 9y agoResetting via link alone is yet another bad thing, because as you pointed out it leads to the exact situation you just described. Password resetting should involve some type of challenge/response, and accounts should be secured with 2FA on top of all that. Medium still isn't winning any security points here.
- mrbabbage 9y ago> Medium still isn't winning any security points here. Sure they are. Removing a credential—in this case, passwords—is strictly more secure. It's the same rationale as to why 2FA with just a TOTP app is more secure than TOTP app + SMS backup. And the emailed links are analogous to password reset links so there's no erosion of security there, provided they're properly secured (one time use, time bounded, etc.). Also, realistically, if they used passwords, many of their users would probably re-use the same email,password pair at other sites. If any of those other sites use bad password hashing hygiene AND get hacked, then the users' account security is busted.
- Jtsummers 9y agoSomeone posted something like this 1-2 years ago here. They used a Yubikey (?) with TOTP to give one-time read-only (?) access to their email while traveling. They posted the project on github, I believe it was a Show HN but I cannot seem to work out the search-fu to find it. EDIT: Ok, TOTP was wrong in my recollection. They use pregenerated one-time passwords: https://news.ycombinator.com/item?id=12255833 https://news.ycombinator.com/item?id=12255833
- vit05 9y agoYeah, it is a little different if it is pre-generated. And if you face a situation where you need access your email from an unsafe computer, it is probably because you can´t use your smartphone. So, two steps authentication is not a great option. And from my experience traveling, this kind of situation happens a lot. Edit: Apparently LastPass has this option: https://helpdesk.lastpass.com/your-lastpass-icon/loggin-in/one-time-passwords/ https://helpdesk.lastpass.com/your-lastpass-icon/loggin-in/o...