48 ms·
A future without passwords
- FpUser 5y ago>"A simpler..." You are not the first to twist the meaning of words.
- degenerate 5y agoeggs, meet basket
- hinkley 5y agoTurning your $800 personal electronics into the moral equivalent of your physical keychain sounds like a good idea to technologists but it really, really isn’t. I’ve stolen your phone and also can access your bank accounts? Is it my birthday or what? Watches are better this way because you don’t ever set them down (and they’re cheaper), but I suspect pickpockets have some things to say about those magnetic clasps. Something in your wallet or with your keys would be best but then you can’t interact with it easily. Those little physical security tokens you’d put on your keychain were always a PITA.
- StavrosK 5y agoThey're only a PITA to me because my keychain isn't close by. Otherwise, I touch the phone to my keychain and that's it, I'm authenticated. What's painful about that?
- sam_lowry_ 5y agoI have a Yubikey Nano permanently inserted in my Mac. It's always there, at the press of a finger.
- StavrosK 5y agoI have one of those too on my work laptop, it's the most convenient thing ever. Not great if you have multiple computers, but it's great for a single one. Then again, your Mac already has a TPM chip you can use.
- livre 5y agoThis worries me a lot, just having a dynamic IP in a third world country is enough for Google to lock you out of the account even if you had typed your password correctly. I would never trust them with my access to other sites, one simple mistake of logging in with a different IP and will leave me locked out of all my accounts. In the name of security they ask you to associate a phone number to unlock the account even though that makes little sense since anyone with the password can then provide any number and steal the account.
- hinkley 5y agoThe dystopian novel practically writes itself. Imagine being locked out of your house and bank accounts because your Google account got suspended. Maybe Google could introduced an account protection service for people worried about this happening - for a small annual fee of course - and unofficially turn it into racketeering.
- rolobio 5y agoAm I the only person who loathes this form of 2FA? I have this on my eBay account and it never works. I click the "Approve" button, and it fails to send so I can't login. I would prefer to just use my 2FA TOTP app, which has yet to fail me! My work has the same sort of setup, they expect you to install the "Microsoft Authenticator" app (no TOTP supported) and click approve in that. But how have we increased safety when my Team/Outlook phone app requests that I click "approve" on a different app? I'm basically alt-tab'ing and clicking a different button, not really an improvement. It should be on a separate device, or something out of Microsoft's control so they can't screw it up. Worse still is SMS 2FA, which appears to just be an analytics technique rather than a security feature. As we know, a phone number is only as secure as a carrier's most-tired employee.
- StavrosK 5y agoI would rather use FIDO2, which is an open, decentralized standard that's both super secure and convenient. Why is nobody supporting that? That way we don't even need to remember usernames, let alone passwords.
- ziml77 5y agoI was really hoping that would catch on when I got my first yubikey some years ago. So far it seems that basically no one is using it. Which really sucks because it's so much more secure. Makes it impossible to accidentally send credentials to the wrong site.
- StavrosK 5y agoSame :( There are plenty of sites using U2F, but not WebAuthn. I hope that's because it's still relatively new.
- Hamuko 5y agoI've yet to run across one browser / operating system combination where WebAuthn is implemented well. Stuff like assertion interface not showing up if you have two authenticators present. Browser and OS vendors should really fix their shit before any mass WebAuthn adaptation happens.
- teeray 5y agoI’m not crazy about these “consult your phone to log in” things. There’s just so many more moving parts. Sometimes the push notification doesn’t make it through. Other times the acknowledgment from the phone doesn’t make it back. Occasionally my phone is doing updates when I urgently need to log in. I’d love for the “something you have” to be “my laptop.” It has a TPM; we can do this securely. Something like the MBP’s Touch Bar where there is a separate integrated physical device with a screen that can make security prompts is ideal.
- StavrosK 5y agoYour laptop (probably) already supports FIDO2 with your TPM, now it's a matter of Google (and others) implementing it.
- sam_lowry_ 5y agoThey have it already in WebAuthn in a completely siloed way. That is, they only implement hardware token support and if you want software tokens, they will make your life painful.
- md_ 5y agoDesktop (i.e. non-portable) WebAuthn authenticators are good for things like transactional authorization (e.g. confirm a payment on PayPal), but not especially useful for authentication: if you already have your WebAuthn secrets on your browser (or OS), you probably also have your authn cookies, too! I'm glossing over a few things (e.g. WebAuthn credentials can be stored in secure hardware, so can be more secure than cookies), but in general, WebAuthn secrets stored in a desktop TPM, while valuable in certain applications, aren't alone a very meaningful step toward getting rid of passwords—since passwords are primarily used for authenticating on new (never-before-used) endpoints. A slightly degenerate case is one where you use passwords to sign into your (say) MacBook, but Apple syncs the WebAuthn credentials via iCloud so you don't need a password on any other services. Which, like, if you're gonna do this—why not just use Apple's password manager and sync passwords? :)
- 5y ago
- tgsovlerkhgsel 5y ago> Soon we’ll start automatically enrolling users in 2SV if their accounts are appropriately configured I get that this makes accounts more secure, but I'm more worried about accidentally getting locked out because my phone isn't charged/nearby/working than getting phished. I really hate it when sites take your ability to choose away, even though I understand why they do it. I wish the EU would regulate that sites must implement U2F (with proper support for multiple keys) so at least you don't have to deal with 100 different (and usually annoying) 2FA methods (often the insecure SMS 2FA).
- hinkley 5y agoSo when my phone battery is dead and I try to log into my computer to tell everyone I’m going to be late, I can’t message them because my phone battery is dead. Awesome.
- teitoklien 5y agoEveryday it feels , tech is going backwards instead of forwards :/
- tialaramex 5y agoU2F is obsolete. Greenfield deployments should be of the standard, WebAuthn, instead.
- kevincox 5y agoThis was my thought too. How many people are going to be auto-enrolled then get locked out because they dropped their phone in a lake. Either this is going to be a huge issue or they are going to provide ways to reset your second factor. In which case is it really 2FA?
- iou 5y agoWhat a nothing-burger article. Just sounds like more lock-in with Google, why is this interesting?
- mjparrott 5y ago"Without passwords" ... by importing your passwords to google! haha
- rpdillon 5y agoThis caught my eye as well! I was expecting something about authenticating without passwords only to discover a post about...Google's password manager.
- NotPractical 5y agoAgreed. This article can be compressed to: * Google is marginally increasing security by turning on 2FA automatically for some accounts * Google's password manager has a new "import" feature Based on the title, I expected maybe some radical new developments in WebAuthn or similar password-replacement technology, not incremental improvements to Google's products that benefit only Google users.
- fsflover 5y ago> why is this interesting? Because people should know what Google is actually doing.
- rEgfAt6xD 5y ago> We’ve recently launched our new Password Import feature which allows people to easily upload up to 1,000 passwords at a time from various third party sites into our Password Manager (for free). But the only way to manually add one password is to craft a custom CSV and upload it.
- pmlnr 5y agohttps://myaccount.google.com/signinoptions/two-step-verification https://myaccount.google.com/signinoptions/two-step-verifica... > Google prompts > "To stop getting prompts on a particular phone, sign out of that phone." Well, f* you too. I genuinely hate this idiotic future where I'm not given a choice. I have a yubikey, a TOTP, and backup codes. Leave my phone out of this.
- balazer 5y agoGoogle has chosen poorly in forcing Google Prompts on all signed-in phones and tablets when 2-step verification is turned on. It nullifies the extra security of a hardware key, turning all of your phones and tablets into weaker second factors, whether you want it or not. To disable Google Prompts and just use your YubiKey's U2F, you could enroll in Google's Advanced Protection Program. But then your TOTP and backup codes would stop working, as would any third-party apps that need access to data in your Google account. The YubiKey, by the way, is a great hardware TOTP key, in addition to being a FIDO U2F key. TOTP has an advantage over U2F in that you can keep backup copies of the TOTP secrets. Of course TOTP is less secure because it is phishable, but U2F is a real pain because you can't make backup copies of the key.
- d110af5ccf 5y ago> U2F is a real pain because you can't make backup copies of the key Dogma: If it isn't backed up then it doesn't exist.
- dandanua 5y agoImpossibility of U2F key cloning is a security feature. As a backup you use another keys, registered in the same service.
- balazer 5y agoSure, not being clonable is a security feature, but it's a huge pain to keep multiple keys registered on all of your services. For real backup resiliency, you should have at least 3 keys, one of which you keep off-site. Presumably you keep one at home and one with you. Want to sign up for a new service? I hope you're at home where you can access two of your keys to register them. Then sometime later you need to go to your off-site location to swap that key, bring it home, and get it registered also. Do that periodically so all of your services are on all 3 keys. Unclonable hardware keys work well enough when it's for a corporate service. Lose the key? Just visit IT and have them give you a new one or overnight it. But unclonable hardware keys are a huge pain when used personally with multiple services. TOTP secrets, while less secure, are much easier to manage. You can write them down, store them on a USB stick, or store them in an online account. You can send them in a message or even read them over the phone. Ultimately the average user is more concerned about losing access to their account than being attacked by a nation state.
- qzw 5y agoAm I the only one who doesn’t want a future without passwords? There are problems with them, of course, but all the alternatives also have serious usability/security issues. And just when we’re starting to get wider 2FA adoption, companies want to get rid of one of the factors. So we’re back to one factor that’s ultimately secured by a device password/passcode anyway. Plus if/when you’re not able to access the device, it’s much more painful to deal with. Not sure we’re really making that much progress.
- ProAm 5y agoNo only that anytime you use Google's 2fa, you let them know where you are and what you are doing. Privacy is a commodity we have willingly and unwillingly given up.
- staticassertion 5y agoWhat is "Google's 2FA" ?
- ProAm 5y agoIt's the Google Sign In prompts when they moved away from SMS for 2FA [1] [2] [1] https://support.google.com/accounts/answer/7026266 https://support.google.com/accounts/answer/7026266 [2] https://www.forbes.com/sites/zakdoffman/2020/06/17/google-confirms-powerful-new-security-move-impacting-all-users-goodbye-sms/ https://www.forbes.com/sites/zakdoffman/2020/06/17/google-co...
- staticassertion 5y agoAh, got it thanks.
- PeterWhittaker 5y agoThey have a range of second factor options, including simple SMS to your phone, the use of their authenticator app (which presumably uses TOTP ([1]), and which could therefore be replaced with compatible alternatives, e.g., LastPass's authenticator app), or USB keys containing a second factor (possibly TOTP-based). [2] has an overview of Google's TOTP implementation. They all do the same basic thing: userid and password let them know who you claim to be, which they validate using one of the second factors listed above. [1] https://tools.ietf.org/rfc/rfc6238.txt https://tools.ietf.org/rfc/rfc6238.txt [2] https://en.wikipedia.org/wiki/Google_Authenticator https://en.wikipedia.org/wiki/Google_Authenticator
- colinrand 5y agoIf Google has my passwords, can I trust them not to crawl sites using them?
- clircle 5y agoWhy don't web browsers have good password managers (like keepass or bitwarden) built in? It seems like a good solution would be to make random password generators more usabile than to throw out the baby with the bath water.
- noisem4ker 5y agoThere's Firefox Lockwise: http://lockwise.firefox.com http://lockwise.firefox.com Firefox also introduced a feature that offers to generate a secure password when it detects a sign-up page.
- clircle 5y agoThanks, yes. I'm a firefox user and I had no idea about this. Just goes to show that these kinds of software should be more usable, discoverable.
- larrybud 5y agoYou can do this with the new version of Edge: https://support.microsoft.com/en-us/topic/use-password-generator-to-create-secure-passwords-e9247e35-684b-4114-bb5e-fdea3e4ae3ff https://support.microsoft.com/en-us/topic/use-password-gener... And https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-password-manager-security https://docs.microsoft.com/en-us/deployedge/microsoft-edge-s...
- gspr 5y agoGood password managers are a dime a dozen.
- clircle 5y agoSure, but why aren't people using them? There's a disconnect between implementation and usage.
- CountDrewku 5y agoA future without passwords conveniently fixed by Google's password manager. No thanks, not giving Google anymore of my info. They have enough already. This post is just marketing.
- twobitshifter 5y agoMy sister was divorced and had to split her phone off from the shared plan. Not wanting to bother her ex, she just changed her number and got a new phone. A week or so later she tried to sign into Amazon: She knew the password but they wanted the 2 factor on her registered device. That device was traded in. That’s ok, the backup plan was to send a code to your phone number on record… of course this fails as well. It can get very aggravating when 2FA goes the wrong way and people don’t believe you are who you say you are. Assuming that users will always have the same device or the same phone number is an obvious mistake.
- CrendKing 5y agoAmazon is a pretty bad example because it does give you backup codes to override 2SV. But for most properly implemented sites, if your sister had the backup codes, that issue shouldn't happen.
- speedgoose 5y agoI doubt that most people keep the backup codes.
- sirsuki 5y agoPlease can we get this more attention: https://sqrl.grc.com/ https://sqrl.grc.com/
- tialaramex 5y agoSQRL requires that web sites re-engineer their user authentication, the same cost they'd incur for implementing WebAuthn. SQRL also requires users to get some additional software in order to work. Of course (this being Steve Gibson) that software is perpetually unfinished and buggy, and may not even be available for your browser (e.g. Safari) - but the next version will always be great... But then unlike WebAuthn SQRL's anti-phishing protection is marginal, it might work, unless it doesn't work, and then it's your fault for not carefully matching things, a task machines are good at and humans are bad at. Use WebAuthn.
- FpUser 5y agoLetting Google manage my passwords to Google. Thanks but no thanks. Great fun awaits those who would fall for this and Google later decides to cancel their account for whatever reason their AI will have managed to concoct by then.
- forgotmypw17 5y agoThe thing I like about the password is that it does not involve any additional technology dependencies. GitHub is going down this road, too, announcing that they will soon disallow password-based auth on git operations. I'm not sure if I will keep using it after that, because having to log into the website from every workstation, some of which may not even have a browser "good enough" for github.com, is more extra work than I'm willing to attend to.
- mplanchard 5y agoCan you still use ssh keys? I haven’t used http for git in years. I store the SSH key’s password in the keychain and then I’m good to go.
- Camas 5y agoYou can. You can also create tokens that function the exact same as a password but with a customisable scope.
- teitoklien 5y agoGitHub’s implementation is quite well tbh They do allow you to generate OAuth codes with scoped access , which effectively acts exactly like passwords just giving more control to you and ensuring your account is safe. I don’t think GitHub’s implementation is ill intentioned at all, When compared to Google’s where it’s now effectively forcing me to keep using the gmail app Because of these prompts :/
- 40four 5y agoTLDR: There is no actual talk or details of how the future without passwords would look or work. It’s just a blog post about Google patting themselves on the back for how ‘awesome’ they are at keeping your passwords safe, and promoting some of their recent and upcoming tech to help manage passwords.
- paulpauper 5y agoThe biggest threat is not the password but the recovery email being hacked or google locking out your account if you supply a phone but are unable to verify it after changing your location. That will lock your account. As always google always misdiagnoses the problem which they themselves helped create.
- deleted 5y ago[deleted]
- radicalriddler 5y agoI don't carry around my smartphone, just a nokia. I hate this approach with a passion. Please just send me a text message, or an email to confirm my login as a second factor to my password, and then trust the IP on user decision. Please don't make me use a smartphone app.
- deleted 5y ago[deleted]
- fuzxi 5y agoSMS 2FA is incredibly insecure. It has a huge attack surface: a stolen SIM card, a MITM attack (SMS is not encrypted, and devices like the Stingray that pretend to be cell towers to gather data are already in widespread use), or good old social engineering to convince a cell provider service rep to port out your number or issue a new SIM card.
- stan_rogers 5y agoSMS 2FA doesn't require purchasing an additional device that's only used for a 2FA application (and has crap battery life if used as a phone).
- atatatat 5y agoI got 29 hours out of my Pixel last charge.
- perryizgr8 5y ago29 hours is downright disgusting, when compared to feature phones battery life. Some of them have 20-30 days of standby.
- atatatat 5y ago7 hours of that was Hotspot WiFi to two laptops in the park and playing tunes. shrugs
- vzaliva 5y agoIn a "future without passwords" every signle web site will use their own app for 2FA, forcing you to install all of them. It should be possible to have one common open standard for "push" 2FA apps and let consumer chose which app to use. Like we have now with Google Authenticator, andOTP, DuoMobile, etc, but with unified "push" functionality.
- StavrosK 5y agoOr we can use WebAuthn.
- tedk-42 5y agoI like passwords. I feel like a baller remembering my complex ones for important sites and other mechanisms for simpler sites - it might take a few attempts sometimes but it feels good and I can do it anywhere without requiring additional forms of auth
- graiz 5y agoI want a future without passwords, but that future gives me the choice of third parties to host my passwords. I prefer 1Password, some people like iCloud, while others may prefer a Microsoft solution. Passwords suck and we need a per-site password policy that can act like an API. Kind of like a Robots.txt, to declare, "This site needs 8-20 characters, 1 symbol and the URL's for login, reset and forgot password are these URI's."
- easton 5y agoLike these? https://developer.mozilla.org/en-US/docs/Web/HTML/Element/input/password#additional_attributes https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in... 1Password (and iCloud Keychain, maybe?) can read these off of the input element and use them when they calculate the password.
- bo1024 5y agoOr ditch site passwords and use public key authentication, like ssh has used for decades...
- christianbeeke 5y agoYes! What could be/are reasons to not do this?
- md_ 5y agoThis is the goal with WebAuthn and FIDO.
- parliament32 5y agoThis is already built into all browser and works great, as client-side SSL certificates. Nobody uses it though because you can't trust users to manage their private keys properly.
- D-Nice 5y agoAs someone whose main project surrounds passwords, I could appreciate a future without passwords, because I consider most existing solutions to be quite poor. However, this feels more like having your sheep be herded by a fox... Many here have already mentioned great points retorting this, so I won't beat a dead horse. I will take the selfish opportunity to mention what my solution is that I'm working on: https://app.SrsPass.com https://app.SrsPass.com There's some rudimentary docs with a spec outline for those interested. But to sum it up, I share the same fears as others here of one device being some ultimate honey pot, or even worse, losing everything I have due to corruption or losing a/all devices where your pass vaults are when it comes to traditional managers. (Mind you, this coming from someone that runs RAID-Z3 NAS in multiple offsites). Basically to keep it simple, I required the following aspects - Available-source or Open-source (duh) - Accessible on just about any device with a cpu, arm/x86 etc - Vaultless & as stateless as possible - No cloud, works completely offline - Uses modern cryptography with sufficiently strong parameters - Requires only one password to memorize - Has uncrackable generated passwords (aka not feasible to crack in a long time period such as with 128 bits of entropy). I believe SrsPass to meet all those aspects already. That is not to say that there aren't more features being worked on (the workboard is essentially public), however, I think you'd be hard pressed to find a more secure (when you build & run yourself) and accessible password manager than it.
- tialaramex 5y agoThere already is a future without passwords, it's WebAuthn. The key element that didn't make your list is phishing. The next threat to Joe Average once he isn't reusing a crap password is phishing. Joe goes to a site which he thinks is the right place but it isn't, it's actually run by bad guys and then Joe gives them his credentials and helps them break into the real site Joe thought he was visiting. Better passwords make no difference to that. Some types of password managers might slow Joe down a bit, as he needs to override a default presumption that this is the wrong site, but since the site has tricked Joe already this is very fragile. TOTP makes no difference, SMS of course makes no difference, and even the Google Auth tech AFAIK makes no difference. But WebAuthn just stops this attack dead in its tracks.
- 5y ago
- segmondy 5y agoI built something like this about 5 yrs ago, applied to YC and they said nope. This is the future, password sucks. The only issue with this is there's still a password in the background and you still have to register. My solution was no signup forms, no passwords. You click one button to sign up to a site, you tap your phone to sign in. This kinda shouldn't belong with Google tho, Google, Facebook wants to use this to keep you to lock you in to their ecosystem. A 3rd party that does only this with absolutely no lock-in is ideal.
- whateveracct 5y agoGoogle is full of shit as always
- paranoidrobot 5y agoI don't trust Google to fill this role of being arbiter of access to things. After it took me a week to recover access to a GSuite account that I knew the password for (long, unique, stored in a password manager), that I could confirm access via the recovery email, and that had my phone number attached - but Google were insisting that I was a hacker, and Support-robots refused to help me or assign a human until I found the secret Konami Code that summoned a human. That experience was exceedingly frustrating, and has killed the last ounce of trust I have for them to do anything for which I might rely on. While they have neat technology, if you fall into one of the cracks, it's near impossible to get support.
- NL807 5y agoPretty much what happened to an email address of mine. I'm migrating away from google.
- ahofmann 5y agoI had to invest 50 € to buy back my old phone number for a week to get to my old Google account. I had password, backup email address, could answer the questions. But the google bots insisted on sending me a SMS to a number that didn't existed. There are many points where I lost trust in google, and this was one of them.
- 88840-8855 5y agoI really dislike 2FA when it is linked to a phone number. There were so many situations where 2FA made huge troubles to me, e.g. I traveled to Asia before Covid, lost my phone. No problem, it is just hardware, I got a cheap 100 Euro Xiaomi phone around the corner and a local SIM card. But I could not login to my Gmail account to get the booking confirmations + addresses of hotels + flight ticket confirmations. It was pain, pure pain. Apple forces me to instal 2FA, but I just don't want. I cannot use a third party app or tool but must use my phone number. This is pure pain to me, because I want to use things like Apple Cash or AirPlay from the phone to the AppleTV. Is there a better solution? I dont know. But 2FA, especially when linked to a phone number, is terrible - at least from my usability point of view.
- alberth 5y agoTitle: “A future without passwords”. Then goes to show the user entering a password in the demo. Doh. https://storage.googleapis.com/gweb-uniblog-publish-prod/original_images/Google_TSA_v02_1.gif https://storage.googleapis.com/gweb-uniblog-publish-prod/ori...
- deleted 5y ago[deleted]
- anfilt 5y agoIf its not TOTP or HOTP, no thank you. I am not gonna use a site specific app for 2fa.
- matt_f 5y agoIt looks like Google 2FA will support using a Yubikey or something like it, which in my mind is preferable to being required to use the Google mobile app. > You'll enter your password [...] Then, a code will be sent to your phone via text, voice call, or our mobile app. Or, if you have a Security Key, you can insert it into your computer’s USB port. https://www.google.com/landing/2step/#tab=how-it-works https://www.google.com/landing/2step/#tab=how-it-works
- PikachuEXE 5y agoFree is the most expensive one I am using 2FA with backup code stored and using unique generated passwords for each service It's not easy nor simple but still better than trusting Google that offers "free" service and wanting "something" in return
- bawolff 5y agoSomewhat controversial opinion: The biggest problem with passwords is that users select them, and users are stupid. We would get 95% of the benefit of 2FA (For forms of 2FA that aren't yubikeys, as yubikeys have benefits related to phising, but nobody uses them so its moot) if websites chose passwords for users instead of the user choosing the password. In particular, the only two threats that 2FA as widely implemented on websites protect against are password reuse, and weak passwords. Both are the results of users choosing stupid passwords.
- timwis 5y ago2FA adds more value than that - it’s meant to be about “something you know and something you have” (in theory, physically). That way, even if your password is compromised three something like a data breach, you’re still protected.
- bawolff 5y agoIf the server in question is data breached, than they'll steal the 2FA secret. If the user's cell phone is breached, they will steal both the 2fa token and the password (or just the session cookie). Well what you say is true in theory, its not true in practise of how 2FA is commonly implemented.
- timwis 5y agoGood point, but wouldn’t they also need the time based algorithm? Here’s some more ammunition for your argument though: https://www.csoonline.com/article/3272425/11-ways-to-hack-2fa.html https://www.csoonline.com/article/3272425/11-ways-to-hack-2f...
- bawolff 5y agoThe time based algorithm is standardized though in https://tools.ietf.org/html/rfc6238 https://tools.ietf.org/html/rfc6238
- countmora 5y agoI use 1Password and it offers dedicated 2FA fields where it generates the tokens for you. It might go against the second factor in 2FA, since the password and token comes from the same source, but it protects me against potential data leaks where my password might be included. But for me, the biggest benefit is having to remember just one password to unlock 1Password which then lets you copy or autofill your passwords. This is why I even don’t know my actual password for such sites since they are auto generated arbitrarily characters.
- dusted 5y agoWon't this make my telephone service provider + phone a single point of failure? Good thing it's not SUPER EASY to steal someone elses phone number, and also a good thing that modern smartphones basically NEVER break. I think I'll just stick with my FinalKey which I can build extras of and which can store the encrypted database and backups offline.
- ur-whale 5y ago> A future without passwords No, thank you, especially if Google is going to be the gatekeeper. https://github.com/pcarrier/gauth https://github.com/pcarrier/gauth FTW
- perryizgr8 5y agoNo, thanks. I don't want to pick up and unlock my phone every time I need to log into my account from a PC.
- necovek 5y agoI recently couldn't log in to my Google account on a new device (with a strong password) and the best I got from Google was an email how my login was blocked for security reasons without any indications on how I can say "hey, it was me". Thank you Google, but I'd rather keep my password than you worry about my logins. You don't know how valuable this account is to me, and what kind of protections I want for it (it's an account I use solely to set up play store on my otherwise de-googled phones).
- tokamak-teapot 5y agoI've just been to check my 2-Step Verification settings on a Google account to see if I could remove SMS as a 2nd factor yet. I've been wanting to remove it for a long time as I don't trust it. I thought I'd try adding a 'Security Key'. There was an option named 'Google' so I chose it to see what it meant. I was immediately presented with: Success! Security key added Your Google security key was added to your account. When you sign in with 2-Step Verification, you'll use your password and your Google. Make sure that Bluetooth and Location are on. When you're signing in, Bluetooth & Location are needed to check that your devices are near each other. Bluetooth pairing isn't required. Works only on Chrome Built-in security keys currently only work on Chrome So I'll use my password and my ... "Google"? I'm guessing this is related to the Google phone app, but if I go to add another security key I can see 'Google' is now disabled and it says next to it 'Last seen 8 February' ... but I've opened the Google app on my phone more recently than that, because I've used it for 2FA for this Google account before! I don't understand "Works only on Chrome". Is this saying I can log into Google on Chrome (desktop) by using the Google app on my phone? I've got 'Authenticator app' set up already (not using Google Authenticator - you can use the code it provides to add to Authy or 1Password or whatever you like). I also have backup codes as a paper copy ... so I think I might now be safe to remove 'Voice or text message' as a backup option, but I'm still wary of doing so.
- gverrilla 5y agoRelax guys the smartest people in the world work for google. LMAO
- modshatereality 5y agoJudging youtubes (javascript) performance trend observed in the exact same browser build on the exact same hardware over a multi-year period, time to abandon ship fellas.
- xyzzy21 5y agoThis can't be done safely or without putting yourself in the hands of one central authority that likely DOES NOT DESERVE your trust. Just HELL NO!
- smusamashah 5y agoIf someone got access to your chrome, they got access to all passwords. Just go to the website, let it fill the password and grab the filled password.
- kevincox 5y agoYes but "got access to your chrome" is far far above the common threat level of most people. Physical access is a huge barrier. Sure, if you are being targeted than your phone or laptop being stolen while unlocked is a problem that you will need to address, however for 99% of the population this is a perfectly adequate level of security. Most importantly it is far better than the most common solution of using the same (maybe slightly modified) set of passwords everywhere.
- rad_gruchalski 5y agoImagine that your google account gets suspended and all your passwords are now gone. No, thanks!
- WealthVsSurvive 5y agoCan my government simply issue me a card that looks like this, https://en.wikipedia.org/wiki/Estonian_identity_card https://en.wikipedia.org/wiki/Estonian_identity_card, wherein one side has an official ID chip and the other side has a user-managed chip for solvent identity? Then, we can all stop mucking about with this or trying to hock something.
- smsm42 5y agoI've seen several sites that don't have permanent password at all. You just tell them your email/phone no, and they send you the temporary password, which expires after the short time. Looks a bit unusual, but the security is not much different from any site that has password recovery by email/SMS - if somebody gets control over your email, you're toast, otherwise you're ok. I wonder why more sites don't do this...
- teitoklien 5y agoI guess to reduce friction for signing in Most apps are not significant enough that people will go through the pain of checking their emails to get the new temporary password Also , a lot of email clients still use STARTTLS while communicating with mail servers to fetch emails , which means a MiTM can reduce that connection to plain text (isp’s have been caught doing this before to read people’s emails) and then steal your password. A site that enforces a rule like that must guarantee that its user’s email server only allows TLS only handshakes on client side (which is difficult if not impossible to do 100% of the time) So even if the idea is great , due to the state email is in , it’s pretty risky and unsafe to MiTM attacks and network inspection.