9 ms·
Imo one key point is missing: Don't give users the option authenticate via Google or Facebook. While it may be convenient at signup, it creates an unneeded depe
by davidwitt415 8y ago
Imo one key point is missing: Don't give users the option authenticate via Google or Facebook. While it may be convenient at signup, it creates an unneeded dependency and confusion if you forget how you log into a certain site.
- mises 8y agoLots of dev tools do this with github, too. The idea of a web-wide sso is a bad one.
- AnIdiotOnTheNet 8y agoI don't think that's true, it's just never been implemented in a way that wasn't bad. You could, for instance, let people have a public key to identify themselves. Your browser or other client could automatically submit your chosen key for you (or expose a button for you to submit it), then there's a challenge and response, and you're logged in. Your account details are stored with the public key as the id.
- Ayesh 8y agoMy developer self loves this idea, knowing that my secret key doesn't even leave the computer. My traveler self hates the idea, because I can't read my emails from my friend's phone when my phone is broken during our 6 month trek.
- mises 8y agoMy security self hates this idea, because a single point of failure is not a good design. How would the key be revoked if lost? Replaced? This seems to necessitate a CA-type infrastructure (like TLS certs). Not something I'm comfortable trusting any corporation or government with.
- AnIdiotOnTheNet 8y agoIf the account is that important to your life, then there are probably other identifying information associated with it, credit card numbers, addresses, etc. Do what you do today when identities are stolen: contact the company, prove you are who you say you are, and the'll let you assign a new key to your profile. Otherwise, who cares? Gen a new key and get on with life.
- sowbug 8y agoChange public key to public key(s), add necessary design elements to stop MITM and replay attacks, and you have reinvented U2F.
- frosted-flakes 8y agoIn that case, I don't mind, since that dev tool probably has access to my GitHub account anyway. Like Netlify, which automatically re-deploys the site when the watched repo+branch is updated.
- Someone1234 8y agoIt is funny how trends shift. A few years ago there was a glutton of articles telling us that we cannot do authentication correction, and to just offer single-sign-on via Facebook/Google instead. Now everyone is back to doing their own home-grown, and Facebook/Google authentication is seen as bloat.
- postalrat 8y agoSo everyone is happy with depending on a password manager? Because having 100 different passwords and having to rotate those isn't going to happen any other way.
- smacktoward 8y agoNobody is happy with it, but it's the least bad of a series of pretty bad alternatives.
- ocdtrekkie 8y agoThere is no reason anyone needs 100 different passwords and/or those passwords to rotate. This is terrible advice, you don't need it and you shouldn't do it. As of current, haveibeenpwned hasn't found any breaches connected to my current email address, which I switched to around three years ago. Which is to highlight: Most breached password data is really, really old. A surprising number of breaches come via an email address I was only signing up for accounts on more than six or seven years ago. Furthermore, most of your accounts don't matter. Things like your email, your bank, your web hosting, need to be secured well. An account you used once to sign up for a newsletter does not. Don't save your credit card info in every single web store you log into, and your security on those accounts don't matter either. Focus your security and your password uniqueness and complexity on accounts that matter, and stop caring about ones that don't. People have reached security overload after being told all of their accounts must be secured, and then offloaded the problem to a bad solution.
- elfakyn 8y agoThat's dangerous advice. Having access to some (or a combination of) "less-secure" accounts could allow an attacker to get enough personal information to escalate privileges through reset fields, social engineering in customer support, or just plain weird interactions between accounts. Besides, most people have enough "important" logins (social media, email, amazon, bank(s), computer, cloud accounts) and some have lots that there's no good reason not to use a password manager. Even with 6 passwords to remember (plus a 7th for all the non-sensitive accounts), it's hard to make them unique enough, and if you end up with a system it's pretty easy to infer the rest of the passwords. Imagine this scenario: you are an average person. You have 90 accounts each requiring a password [1]. 5 of them you deem sensitive enough to have their own password and 85 of them share a password. One of those 85 is compromised. Now you'll spend all day stressing out whether one of those 85 accounts, in hindsight, is actually something you care about at least to some extent. Desperately trying to remember whether there were any other accounts that you should've secured better. (Anecdotally, this has happened to me before a password manager: I had different logins for important stuff and the same for non-important stuff; it's also happened to most of my friends at some point.) Or you can use a password manager. Once you do have a password manager, you can go ahead and have unique random logins for everything, there's no extra effort needed. 2FA is another important security measure. In regards to rotation, I agree, and NIST doesn't even recommend forced rotation anymore[2]. [1] https://blog.dashlane.com/infographic-online-overload-its-worse-than-you-thought/ https://blog.dashlane.com/infographic-online-overload-its-wo... [2] https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver
- theandrewbailey 8y agoIf a service offers multiple ways to authenticate a single account, I don't see much problem with it. Google killed their standards-based logins? No problem, use one of the other providers you've linked the account with.
- tacomonstrous 8y agoOne way I've seen sites mess this up is when they allow me to sign up using a Google account on my Android phone, but don't offer Google login on their web page. Makes for very confusing UX!
- tln 8y agoIt's convenient at signup and every login, and with a company Google Apps account, especially convenient when a person joins or leaves!
- fernandotakai 8y agoalso, you skip email validation (which is a PITA) and google store's the user password instead of yourself. kind of a win win imho.
- Raphmedia 8y agoA lot of our users would complain that writing on our product support forum was hard. Since we added those option, the friction is gone. People who need help that can be boiled down to "Did you plug it in? Is the battery full? What about turning it off and on again" have a hard time understanding how to register an account. Thinking of a strong password and then figuring out how to click on the confirmation link in their emails is apparently the hardest thing to do.
- kgwxd 8y agoSounds like a scenario where that friction would actually be desirable. If they got far enough to file a complaint they can obviously handle it, they're just lazy complainers, which is exactly the type of user I'd rather didn't make it to the support page anyway. Like you said, their problem usually boils down to plug, charge or reset and they were just too lazy to search the knowledge base for basic troubleshooting, something that should be possible without logging in. Them getting in to re-ask an already answered question is just a waste of someone elses time and useless noise on the support forum.
- Raphmedia 8y agoThat's a good way to lose loyal customers who order many times a year.