3 ms·
> I don't think there's a technological solution to this problem Lol of course there is. 1: IP alerts - new IP? email alert. 2: 2FA - should be standard, req
by tcd 9y ago
> I don't think there's a technological solution to this problem
Lol of course there is.
1: IP alerts - new IP? email alert.
2: 2FA - should be standard, requiring a physical device to login
3: Deterrents; seems slightly fishy? You need to login to the account by proving you are the owner.
With AI it's not so difficult to detect if it's a genuine login (browser fingerprinting, UA strings, version numbers, OS versions etc).
- zaarn 9y agoYou don't need AI. A simple fuzzy string match and some basic rules around it (ie, allow 25% fault across all tests, so your useragent can change 20% and the other strings can change 5% without you needing to reauth). The simplest defense is to never log the user out and only ask passwords for special things (like Github's Superuser Mode)
- bambax 9y agoThose would only help limit login sharing; they're not solutions to the problem of making account delegation easier to do (and to understand).
- TallGuyShort 9y agoI think from most people's perspective all those things do is make login sharing harder. I'm working with a non-profit to set up a website and social media accounts, and I've explained the concept of everyone having their own login to a shared account 3 times, and I think maybe 1 person gets it. (And maybe I suck at explaining it, but I have plenty of teaching experience and usually get compliments on explaining technical stuff in a non-jargony way). If these same people had the obstacle of having to add another person's phone to 2FA as well as share the password, they still wouldn't look very long at alternatives to the way they log in. There's a fundamental assumption that there's a way to log in, and other people just have to do that. Very hard to help them realize that everyone should authenticate as individuals, and you can authorize individuals to access the group's resources.
- noxToken 9y agoThe issue here is still culture. What's an IP, and why isn't this alert going to IT instead of me? 2FA can be added to multiple devices still allowing delegation. People will throw a password into anything that prompts them. I always think about people who say that verification keys in emails is the route to go[0] to stop phishing/fraud attempts. It's a technological method that ensures the message is sent from a specific source, but that doesn't mean that the user will always verify the key. We've had the technology to stop most commonplace security issues for a while. We've almost always been lacking in culture. [0]: https://news.ycombinator.com/item?id=14219272 https://news.ycombinator.com/item?id=14219272