5 ms·
> From the blog post the article cites, those options are: Microsoft Authenticator app, Windows Hello, a security key, or a verification code sent to your phone
by kortex 5y ago
> From the blog post the article cites, those options are: Microsoft Authenticator app, Windows Hello, a security key, or a verification code sent to your phone or email.
Mmm, yup that all sounds terrible. I agree with GP, I like the ability to decide how to manage logging in.
Passwords are a "least worst" kind of system.
- Spivak 5y agoPasswords are a lowest common denominator kind of system. They're an unstructured primitive that people can add structure to in order to create a system. Everyone ad-hoc creates their own and most people are really bad at it. Whether it's memorization, deriving them from some other key, storing them in a HSM, or in a password manager.
- kortex 5y agoExactly, they are the primitives of security systems. If passwords are broken, then every other security system is suspect. If users can't be trusted with passwords because most people are really bad at it, and people are bad at it because they are human, why should I trust MS's human developers to do any better? Why should I trust anyone to do better? Exploitable software has resulted in far more economic damage than bad passwords. It seems like a massive XY problem where somehow many people have come to the Y "let's get rid of passwords" as the solution, when the X is a mixture of solved problems: - "people are bad at entropy" (password gens, sensible entropy rules) - "people are bad at memorizing orthogonal unique strings" (password management schemes and systems) - "passwords leak" (detect wild passwords and facilitate rotation) The humble "secure string" allows the implementation gamut from "hunter2" to kilobits of noise, stored in a browser, chip, or post-it. Just prevent the worst incarnations. Passwords are not broken.
- Causality1 5y agoIndeed. Shit, just this year Microsoft signed a kernel driver containing a rootkit and didn't notice until third parties alerted them three months later. Those are the people you want in control of all your online accounts?
- tialaramex 5y agoBut if you're worried about Microsoft, you shouldn't want a shared secret such as a password. The whole problem with shared secrets is that the other party might lose it. For WebAuthn, even if Microsoft literally makes a web site "Get tialaramex's authentication credentials here" solely to reveal the credentials they have for me, it doesn't help bad guys at all. Completely useless. The credentials only help Microsoft, and only to verify me. That's the "scary" passwordless future, authentication that actually works and can't be weaponised against you, terrifying...
- notriddle 5y ago> Exactly, they are the primitives of security systems. If passwords are broken, then every other security system is suspect. If users can't be trusted with passwords because most people are really bad at it, and people are bad at it because they are human, why should I trust MS's human developers to do any better? Passwords that are managed by hand are broken. If you’re already using an automated password manager, then you’re probably fine. Humans can build tools that do stuff better than unassisted humans can do it. Cars are faster than humans, even though humans built them. Dice are better at generating random numbers than unassisted humans, and they’re literally just marked cubes. Of course, the Windows end-users could build software-based password managers instead of doing it by hand, and some have. But it’s not the default, so many don’t. > Why should I trust anyone to do better? Exploitable software has resulted in far more economic damage than bad passwords. You seem to be underestimating the amount of economic damage caused by phishing and password reuse, both of which can be largely chalked up to manual password management. But am willing to be corrected on this. [citation needed]
- kortex 5y agoNumbers are a bit loose, but even a Fermi style estimation suggests malware in general is worse than phishing. Phishing is on the order of tens of millions [1] to a few billion [2]. Ransomware alone probably causes upwards of many billions [3]. Equifax breach (XML exploit) alone has cost billions. Heartbleed, spectre, meltdown, those are at least 1B each. [1] https://www.cybersecuritydive.com/news/phishing-cost-enterprise/605110/ https://www.cybersecuritydive.com/news/phishing-cost-enterpr... [2] https://www.proofpoint.com/us/corporate-blog/post/fbi-reports-125-billion-global-financial-losses-due-business-email-compromise https://www.proofpoint.com/us/corporate-blog/post/fbi-report... [3] https://cybersecurityventures.com/global-ransomware-damage-costs-predicted-to-reach-250-billion-usd-by-2031/ https://cybersecurityventures.com/global-ransomware-damage-c...
- notriddle 5y agoRansomware isn't necessarily spread by software exploits. A lot of them use nothing fancier than "My File.pdf.exe" attached to an email, like CryptoLocker and its many clones [1]. Sure, WannaCry used an actual software exploit, but most ransomware gangs don't have leaked NSA cyberweapons to work with. [1]: https://www.arnnet.com.au/article/556598/australia-specifically-targeted-by-cryptolocker-symantec/ https://www.arnnet.com.au/article/556598/australia-specifica... Also, a lot of breaches that are caused by vulnerabilities, like large forums having their databases leaked, are bigger problems than they should be thanks to password reuse. But I hadn't thought of Equifax. That company's database held so much economic value that, all in one fell swoop, this single exploit may have tipped the scale so that vulnerable software cost more than password reuse.
- deleted 5y ago[deleted]
- ryanlol 5y agoHow is TOTP terrible? How are security keys terrible?
- dijksterhuis 5y agoParent could be talking more about vendor lock-in rather than protocols. At least that's my bug bear with this. I know 2FA SMS is less secure, but I'm sticking with it as long as MS require a MS app (or I'm forced off SMS 2FA).
- ryanlol 5y agoMS doesn’t require a MS app unless they’ve changed something recently.
- dijksterhuis 5y agoOh FFS! It's a hidden menu option when you go to [1]. Have to click Configure App Without Notifications once you click Setup Authenticator App. Two years of misery and stubbornness. One hidden menu option. [1]: https://account.activedirectory.windowsazure.com/proofup.aspx?proofup=1 https://account.activedirectory.windowsazure.com/proofup.asp...
- soundnote 5y agoAny TOTP works fine, they just advertise their own obviously, and it has extra conveniences for their own accounts.
- kortex 5y agoAh, ok. They make it sound like it _has_ to be their flavor of OTP. That's...slightly better, I guess. I still want passwords though as the base level.
- kortex 5y agoUgh. I just spent the whole day screwing around trying to debug SAML SSO for setting up a VPN on AWS. Brain is fried and I feel no closer to my goal. I realize that's somewhat unrelated to passwords, but my point is "Identify management is _hard_". Passwords just kinda work. That's the _opposite_ of broken. We just need to train out the bad habits (storing plaintext, allowing dictionary words, etc).