3 ms·
I'm beginning to think the only user friendly secure way of user authentication is to go passwordless (except for the email account which becomes the key for ev
by snowwolf 8y ago
I'm beginning to think the only user friendly secure way of user authentication is to go passwordless (except for the email account which becomes the key for everything).
Setup an email account and lock it down - strong unique password, enforced 2 factor, etc.
Then on every site just email a magic login link.
The user only has to remember 1 password, they don't have to figure out how to use (and trust) a password manager, they don't have to worry about a breach on one site leading to all their accounts being compromised, and they don't have to worry about whether some site has correctly implemented 2 factor, or has side channel attack vectors to gain control of their account.
I actually attempt to do this where I can (set a randomly generated string as your password and use the reset password route to get a magic login link). The main problem I run into is where I want to be logged in to the site and their mobile app and they log out all devices when the password is reset.
The biggest problem (and it is a big problem) is that if they lose control of their email account or their email provider is breached, then they lose access to everything. But right now that's already true (due to the reset password route on many sites).
- yogsototh 8y agoThat was exactly what Persona was for. It was marvelous to use. It's a shame that project hasn't gained sufficient traction and closed. https://developer.mozilla.org/en-US/docs/Archive/Mozilla/Persona https://developer.mozilla.org/en-US/docs/Archive/Mozilla/Per...
- thx4allthestuff 8y agoThis is in response to this comment, as well as the parent: Minimize your trust in all-in-one authentication services. A password manager is reasonable (still makes me nervous), because it makes it simple to have a different complex password for every account. But taking Persona for instance, it claims "free yourself from password management". Don't do that. When you free yourself from managing your security, you are not secure. It really is as simple as that. Security takes diligence. One could even say that security is diligence. The harder you make it for yourself, the more secure you are. Regarding the possibility of locking yourself out of your accounts, one suggestion that I have is to have one or more primary accounts that you use to recover all of you less critical accounts, and keep the device used for authenticating to those at home, preferable in a safe. Do not use this device for your normal 2FA - only use it as 2fa and recovery for the primary recovery accounts. For the remaining accounts, use a separate device that you carry around with you. This way when you eventually lose access to something, you'll have a better chance of getting it back. In other words, a lost phone wont necessarily turn into a catastrophe because you've lost your only means of 2fa.
- snowwolf 8y agoThis is all well and good for a tech savvy user. But for the user who "instead of properly setting up their authenticator app, they brilliantly used one of the ten backup codes to finish their 2FA setup (and didn’t even store the rest), thus locking themselves out of their account immediately.", this will all be too complex for them. We need a solution that is actually usable by the masses that maintains a reasonable level of security.
- StavrosK 8y agoThis is wrong. Your email provider is already a SPOF for your security, since anyone who owns your email de facto owns all your accounts. All you're doing is removing another link from the security chain, i.e. the service authentication method. Essentially, you're replacing two (or a thousand) things someone can break into with one thing someone can break into. That's much easier to secure.
- lbriner 8y agoSo all you've done is move the problem to the email account. The original article is about how hard it is to balance usability and security so having 2FA on email creates a problem.
- snowwolf 8y agoNo. I’ve isolated the problem to the email account. You only need to set it up once with a provider who hopefully has the resources to do it properly (like gmail). Rather than having to do it for every website who all decide to do it different ways so it’s never a standard process. And many doing it badly, forgetting to disable account recovery if 2 factor is enabled.
- pat2man 8y agoIf that provider is one of the major ones, you an also use Oauth2 to sign in, no magic link needed. Also its more secure.
- hunter2_ 8y ago> The main problem I run into is where I want to be logged in to the site and their mobile app and they log out all devices when the password is reset. On a technical level, most likely it's that their backend considers all cookies generated prior to the reset to be invalid. In that case, a solution could be to "steal" (from yourself) the one valid cookie that came out of the reset, and place it into your various devices/browsers. So long as they don't hash the user agent string into it or something (which I assume they wouldn't, since the validity of the session survives browser upgrades). Desktop browsers (having dev tools) will let you get the cookies and add said "stolen" cookies. Unfortunately, you'll have a hard time with mobile apps.
- StavrosK 8y agoI like this method so much, that I wrote a Django library for it: https://github.com/skorokithakis/django-tokenauth https://github.com/skorokithakis/django-tokenauth For a demo, see https://www.eternum.io/ https://www.eternum.io/ or https://www.pastery.net/ https://www.pastery.net/.