4 ms·
Anecdotally, getting arbitrarily blocked and locked out of your stuff is the single biggest practical security today problem today for me (maybe it isn't for no
by foxfluff 5y ago
Anecdotally, getting arbitrarily blocked and locked out of your stuff is the single biggest practical security today problem today for me (maybe it isn't for non-technical users who reuse weak passwords, install catpicture.jpeg.exes and random software from the internet, log in using public computers or other people's PCs..).
I don't believe I've ever had passwords compromised. The only time I know I had malware was when I was a kid and installed a runescape autominer.. I've had some close calls with software vulnerabilities (I patched opensmtpd mere hours before bots started attacking it), but that's rare. haveibeenpwned only shows involvement in the last.fm compromise, which is a no biggie since I wasn't 1) using the service any more 2) using the same password with other services 3) using that email address with anything worth caring about.
By contrast, I've been burned by service providers blocking me many many times. They call this security but how is the equivalent of "we decided to take all your mail and not deliver it to you, and changed the locks to your apartment so nobody can get in" security? It's security in the same sense as "we decided to burn all your money so nobody can steal it, hope you're happy."
As a consequence, I've tried to cut out as many services and third parties out of my life as I can. It's an uphill fight though, and most services are hell bent on adding points of failure. E.g. where my bank before supported OTPs (in addition to login & password), now they require a phone too. It's probably not a matter of if but when I get bitten by this; I've had a Samsung Xcover physically break.
I think any notion of security should include secure access for the relevant party. If you can't access your stuff, security has failed (unless it can be demonstrated that there was an active attack going on and the only way to prevent it was to block everyone.. which these overzealous blocking systems in place can't demonstrate).
- toastal 5y agoMy 'favorite' is SMS and other proprietary app-based 2-factor auth. My phone broke while I was traveling through Laos. I was going to be returning in a couple days, I could speak the language well enough, so I didn't have any immediate need to get a new phone (and the pickings were way too slim in a country such as Laos). What I thought would be a good idea was to purchase a new device online to be shipped to my apartment on my return. I tried to log into my online shopping account but most payments are always locked behind 2FA with SMS being the only option. Bank transfers worked too, but that as well was locked behind SMS. So in order to buy a new phone, I needed a new phone to buy a new phone. Almost nothing in the country support TOTP or WebAuthn, etc.. and the times they do they just call it "Google Authenticator" encouraging users give those keys to Google as well instead of supporting FOSS TOTP. At the same time I got my income via TransferWise, and their 2FA is some proprietary BS in their app instead of generic TOTP that I can back up on my laptop. So I couldn't get extra money to my foreign account to pay for it. A few months later I needed to use PayPal and was locked out of my account on similar grounds. My foreign account I didn't have my old phone number because it's pretty customary to rotate numbers on prepaid plans here, and my US account was using Google Voice (because it's tedious to maintain a US SIM card for the 2 times a year I need it) and they removed SMS support for Voice while not giving an alternative for authentication. The best part is that to get support from PayPal about authentication you needed to first authenticate to message support. Needless to say, I straight-up refuse to use PayPal now and direct message vendors about supporting an alternative (either widely or for this exception).