4 ms·
Why exactly do I need a "passwordless world"? I read the prior article, and the two main problems with passwords apparently are pwd-db leaks and email accounts
by usrbinbash 5y ago
Why exactly do I need a "passwordless world"?
I read the prior article, and the two main problems with passwords apparently are pwd-db leaks and email accounts as central password reset mechanism.
A password manager software solves both these problems. I have to remember 2 passphrases: 1 to decrypt my harddrive / backup, one to access my password manager.
Everything else is protected by a truly random, long, unique-for-every-service, password. Yes, that includes my email account. It's simple, it requires no external services, I control it in its entirety, it can be done using 100% FOSS software.
db leak somewhere? So what, the chance of a 64byte random string being bruted/rainbowed is next to zero, and it's used nowhere else. And it takes me all of 10 seconds to set a new password that is just as strong.
And since the pwd-safe is part of my backups, there is no single point of failure involved.
- drewcoo 5y agoFor most of us, passwords suck. There are lots of different rants on the Internet about the insecurity or lack of usability or cost to support passwords. You can keep using them if you like.
- usrbinbash 5y ago> about the insecurity Passwords don't have to be insecure, that's precisely the point of a pwd manager (apart from having a different pwd for every service).
- mr_mitm 5y agoThey're insecure in the sense that you must tell someone your secret. Using a secret key means that the secret never leaves the system, it appears accidentally on the screen much more rarely, it can't be quickly remembered, can't be seen by keyloggers or clipboard monitoring software, ... In an ideal world, we'd be using private keys on something like a smart card secured by a pin for everything.
- usrbinbash 5y agoIf we assume a system compromised to the point where the attacker can install key/clipboard loggers, then private keys (which are usually also secured by a symmetric password that has to be entered on the system) won't help us either. If a level of security is required where even a compromised end user system is not enough for an attacker to authenticate successfully, then MFA is the only answer, and that is not an argument against passwords, because it doesn't matter what the other factors are.
- mr_mitm 5y agoI agree that nothing can save you once your system is compromised. But that is not equivalent to having a keylogger, because physical keyloggers exist (or keylogging via camera, if that suits your definition of keylogger). Clipboard monitoring can also happen accidentally via remote desktop clients or virtual machines. No matter how you slice it, there are many more scenarios where passwords can get leaked compared to private keys being leaked. If everyone used private keys instead of passwords, the total number of compromised accounts per year would be substantially lower.
- usrbinbash 5y ago> If everyone used private keys instead of passwords The only difference between that and using a pwd manager: using a key-pair requires more infrastructure (namely public key repositories). I'd still have a master key to everything (the symmetric key used to encrypt my priv. key).
- noahtallen 5y agoI think it’s mostly for everyone else. I’m very successfully using a password manager. I’ve tried to talk nearly everyone I know into using one as well, and it’s really painful for them. Even for people I can help daily, their setup somehow gets complicated enough that they go back to using their default 5 letter password for new things until I fix it. A password manager can be an extra 10 seconds of work up front in some edge cases — input not detected correctly, signing up in an app, trying to quickly get through a flow when your password manager is logged out… People just revert back to the easiest path, which is their 5 letter password they’ve already used on a billion services. Oh, and another rough edge case is when the autogenerated password doesn’t match the password requirements. Using a disallowed symbol, too long, etc
- daenney 5y ago> Even for people I can help daily, their setup somehow gets complicated enough that they go back to using their default 5 letter password for new things until I fix it. This has been my experience too. For my parents or my siblings no matter what I try we always end up back there. And I understand to a degree, the software is getting in the way of getting something done. I’ve managed to get to the point where at least their email accounts use a non-standard passphrase for them, so the likelihood of it being taken over and used as a reset vector for other accounts is much much smaller. And that’s about the best I can do.
- usrbinbash 5y ago> A password manager can be an extra 10 seconds of work up front in some edge cases There is always a trade-off in security vs. comfort. To me, having a completely secure authentication method that is simple and doesn't rely on any third party services, blorkchains etc. and is completely under my control, is important enough to be worth the occasional 10 seconds of work. > another rough edge case is when the autogenerated password doesn’t match the password requirements Which is why the generator I use allows me to set the character set & max length.
- noahtallen 5y agoWhich is why I use a password manager, of course :) There simply should not have to be this trade off. I know how to adjust the generator for the rules. But on my phone, that’s a fair amount of extra work and you have to know how to do it. For non-tech peers, they won’t know how to learn that, and they’ll likely not understand the trade-off well enough to do it anyways. So we’re back at the beginning: passwords need to be secure by default — without going through any extra steps, or we need a different approach that is secure without extra work.
- Brajeshwar 5y agoTrue for you, me, and most of others here on HN. Unfortunately, almost everyone else is an entirely different story. I know friends, who are well-to-do (even some CTOs of pretty big enterprises), have passwords/CARD-Pins in their iPhone Notes. I have seen a large number of friends and relatives uses Gmail (not their own domain) to store their passwords -- they keep updating a draft that contains all of their lives secrets, passwords, bank details, and what not. It is a different world out there.
- usrbinbash 5y agoI know, and I also know this will never, ever, change, because there is always a tradeoff between security and comfort. But this doesn't mean I need a passwordless world.
- Ajedi32 5y agoIt will change if we kill passwords, thereby making that type of misuse impossible. In my view, the goal of the "passwordless" movement is to take basic security best practices that techies have known and practiced for decades (using unique, random, unphishable credentials for each site), and make them the default for everyone, in a way that's difficult to mess up.
- usrbinbash 5y ago> unique, random How is "killing passwords" a prerequisite for this? I just explained how a pwd manager provides exactly that. > in a way that's difficult to mess up. The first step towards that is designing a system that is simple in its architecture. eg. Private Key Authentication is nice, but requires a public key infrastructure to work at scale. I don't know, but I believe teaching the use of a "password safe" to a non tech person is much easier than giving a lesson on PKI and the x.509 standard.
- Ajedi32 5y ago>> unique, random > How is "killing passwords" a prerequisite for this? It's not; as I said techies have been doing that for decades. It is, however, a prerequisite for making that the "default for everyone, in a way that's difficult to mess up". Password managers are not and cannot be the default for everyone, because it's easier to just reuse use the same weak password everywhere so long as that remains an option. Until that changes, insecure password management practices will be widespread. > The first step towards that is designing a system that is simple in its architecture. Simplicity of the architecture is mostly irrelevant, simplicity of usage is what matters. I agree teaching users how to manually manage X.509 certificates would not be viable, but I don't think anyone is arguing for that.
- davidkuennen 5y agoI already didn't like passwords before. But oh boy did I see the horror for normal folks when I observed my mother battle with a camera app recently. She was so frustrated with the password it was crazy. Especially because there are 1000 rules a password must have to be "safe" these days. And even then, she would just use a slightly different version of her default password. I'm 100% certain she wouldn't remember that password the next time she has to log into that account. So she has to go through the whole password reset nightmare with all this horror again. Terrible.
- usrbinbash 5y agoBut these are exactly the problems a pwd manager solves; It generates long, random passwords, satisfying arbitrary rules that the user doesn't need to worry about. It hides all these passwords behind one master key, which is the only one the user has to remember. Resetting passwords is a non issue, because the pwd manager doesn't forget a password.
- tialaramex 5y ago> generates long, random passwords, satisfying arbitrary rules that the user doesn't need to worry about This requires lots of magic everywhere to make this "work". Every time it fails, the user is left with confusing nonsense. At the weekend the company who took over one of my pensions sent me a QR code for "my account". Well of course it's just a "create account" link but as a QR code. So I create the account, it requires a password. So I pick a random password, nope. "Please follow the password requirements", it's a paragraph of text, including a maximum length, required characters, forbidden characters, combinations, and so on. I had to manually adjust the randomly generated password. Eventually I guessed that although double quotes aren't listed as forbidden they probably are, and that was enough. Now, I know what I'm doing, but realistically most users are going to settle for something easy or worse they are going to give up altogether. Passwords are awful, it's long past time to do WebAuthn
- usrbinbash 5y ago> This requires lots of magic everywhere to make this "work". Speaking from experience with my system: it really doesn't. 99/100 services are perfectly happy with the passwords generated by my default settings (64chars alphanumeric with symbols). I had to manually intervene exactly 2 times so far, and the only param I had to change was the pwd length.
- the8472 5y agoI'd even say that passwordless is an anti-feature because it means you're only secured by something you have, not something you know. For one it means you need backups because the physical object can be lost or stolen and two it's not protected by rights against self-incrimination. What we really need is hardware tokens stills secured by a master password. I think yubikey optionally supports device unlock PINs, but they don't support unicode.
- cameronh90 5y agoWith webauthn, you can require user verification. This is left as an exercise for the authenticator but means the authenticator guarantees it's checked either biometrics or PIN, thus meeting the "have" && ("know" || "are") criteria. If you're paranoid the authenticator might lie to you, you can use the attestation data and only trust the UV flag from tested/trusted authenticators. That said, know/have/are thing is more of a heuristic than a rule. A theoretical system that _perfectly_ tests only "are" could be more secure than a "have" && "know" system, depending on your threat model.
- the8472 5y ago> A theoretical system that _perfectly_ tests only "are" could be more secure than a "have" && "know" system, depending on your threat model. That circles back to the right against self-incrimination part. And a biometric system on its own (without the "have" part) seems like it could be done without verifying intent by just pointing a remote version of the same sensor at a person.
- cameronh90 5y agoWhether that's an issue depends on the threat model of the system you're building, and also the legal context you are operating in. In the UK, for example, biological authentication and password authentication are both treated equally and you can be imprisoned for two years for refusing to provide either under RIPA legislation. Equally the US could (and IMO should) change the law to treat biological authentication as equivalent to password authentication when it comes to the right against self-incrimination. But besides that, a biological verification could rely on someone performing some sort of affirmative action (think "my voice is my password" type systems). Indeed, prior to computers, nearly all authentication was performed roughly in this manner but with humans rather than AIs doing the evaluation. In practice, the authentication part generally worked quite well (but bribing the authenticator was a good "hack").
- cameronh90 5y agoWhat I've been trying out is having the UX strongly encourage a passwordless configuration, but with a password/TOTP escape hatch hidden away. The caveat is, the password must be 64 characters long and is tested for entropy. It also enforces additional security checks that the passwordless option doesn't, to reduce the chance of MITM (which TOTP doesn't protect against). I also don't implement any automatic password reset workflow, because if you're using a password manager then you shouldn't ever need to reset your password. If you do, it will involve manual verification and talking to your account manager.
- willis936 5y agoAnd what of 90% of users that use the same, low entropy password for everything?
- usrbinbash 5y agoAll security systems require their users to be vigilant. This fact will not change regardless of the technology used.
- willis936 5y agoWhy is that? A system that requires users to hold one key depends on less user vigilance than a system that requires a user to hold hundreds of keys.
- usrbinbash 5y agoMy system requires me to hold exactly one key, which is my master password. I don't even know the dozens of passwords I am using. When I require one, the pwd manager enters it for me.
- willis936 5y agoMost users will use the lowest energy option, which is using a reused, low-entropy password. Using a password manager is great for those that choose to do so, but the system can be designed so the lowest energy option is still secure enough. In this light: passwords are not secure enough.
- usrbinbash 5y agoA password manager solves this problem as well. Even if the user choses to use a low-entropy password for his locally stored safe, the actual passwords generated (which the user doesn't even need to know) for the services he accesses will be of high quality, and unique to every service. The only point of vulnerability is then if the device gets stolen/hacked, but that's a proble that one entity has to deal with, instead of a problem that affects millions of users like a DB leak full of weak passwords.
- remus 5y agoWhat you're describing is basically a passwordless setup with a poorly designed API (putting loosely defined strings that can have nowhere near enough entropy) and some great tools that have grown up around that API (password managers). When it's used well (as you do) it works great for all the reasons you describe. The problem is there's lots of room for people to misuse it. Wouldn't it be cool if we could move to a world where by design it was impossible for grandma to share her credentials from bank.com on shady-criminals-definitely-not-trying-to-steal-your-stuff.com?
- codedokode 5y agoIf your computer gets infected by virus, all your passwords will be leaked. In comparison, a physical key cannot be stolen by a virus. Also, using a physical key is much easier for an average user than installing a password manager, integrating it with applications, thinking of a secure password and typing it every time you need to login.
- usrbinbash 5y ago> If your computer gets infected by virus, all your passwords will be leaked. Computers can get compromised, and physical keys can be stolen.