4 ms·
Most people accept that their houses are accessible via a single physical key that - in reality - is mostly security theater as 10 minutes of lock picking lawye
by aboringusername 5y ago
Most people accept that their houses are accessible via a single physical key that - in reality - is mostly security theater as 10 minutes of lock picking lawyer will yeild favourable results depending on your motivation.
And 2FA does not represent the real world. If you lose your house key, you may need a new door, or perhaps a skilled locksmith can make your day a lot less worse.
Yet, in the digital sphere, if you lose your 2FA (or backup codes) your account is lost, forever. There is no "digital locksmith". I dare anyone to test this by losing their "key" and attempting to regain access, there is no other human on earth you can physically contact, especially with Google.
Let me ask anyone here: you've invested over 10+ years of your life working for your house or car. You get a single set of keys. The terms and conditions state if you ever lose your keys you will be locked out, without recourse, forever.
Yet this happens constantly with Google (just search HN, it's practically every week!). If their AI says "you bad, you go bye", your keys are taken away and any of your legally purchased possession's are just taken away, and somehow this is legal!!
We must fix this before mandating strict digital security.
- PlanckMeasure80 5y agoI agree with you but Google has helped me recover my personal gmail account multiple times. The form sends a request which can take them a few days to respond.
- _8j50 5y ago> Most people accept that their houses are accessible via a single physical key that - in reality - is mostly security theater as 10 minutes of lock picking lawyer will yeild favourable results depending on your motivation. It's not security theatre. You have to think in terms if threat models. Majority of breakins happen because someone opened the door or left it unlocked. Like computers, even if the door was 2ft stell that is very hard to open, most houses you can just cut through the wall with a mediocre investment at homedepot. The security of the door isn't a good comparison because having a lock and a keypad for second factor auth won't change much. A pry bar or battering ram away either way. The threat model of locks for regular people exclude threat actors that will go to that length to break in because of various factors including the value of what is behind the doors,etc... your typical crackhead or habitual criminal isn't looking to pick locks or break doors because it takes time, people have doorcams these days and they are too lazy, there are easier targets where people leave keys under a rock, open up if you knock with a pizza box in hand,etc... like cybercrime irl attackers tend to go after the easiest most valuable target. > And 2FA does not represent the real world. If you lose your house key, you may need a new door, or perhaps a skilled locksmith can make your day a lot less worse. There are 2FA locks with pin/key/bluetooth/app combinations. > Yet, in the digital sphere, if you lose your 2FA (or backup codes) your account is lost, forever. Arguably, a locksmith replacing your lock is the same as you having to create a new account. If an online service refuses to reset your credential it is only because you agreed to the Tos, otherwise you have legal means to obtain anything of value behind that account just like IRL. Also, I know people that were robbed and lost all their documentation and it took years to get it all back during which they couldn't get a driver license and most employers couldn't hire them. > The terms and conditions state if you ever lose your keys you will be locked out, without recourse, forever. You keep using strawman arguments. Crappy Tos and company have nothing to do with the discussion regarding authentication mechanisms. A service can always verify your ID and when you are locked out require another id verification to allow credential reset which some cryptowallet providers do. Stop using shitty services by companies like Google. I haven't needed a personal google account in over half a year after cutting out android from my life. Also, security can be good without being strict. And strict security can be bad.