4 ms·
> unique, random How is "killing passwords" a prerequisite for this? I just explained how a pwd manager provides exactly that. > in a way that's difficult to
by usrbinbash 5y ago
> unique, random
How is "killing passwords" a prerequisite for this? I just explained how a pwd manager provides exactly that.
> in a way that's difficult to mess up.
The first step towards that is designing a system that is simple in its architecture.
eg. Private Key Authentication is nice, but requires a public key infrastructure to work at scale. I don't know, but I believe teaching the use of a "password safe" to a non tech person is much easier than giving a lesson on PKI and the x.509 standard.
- Ajedi32 5y ago>> unique, random > How is "killing passwords" a prerequisite for this? It's not; as I said techies have been doing that for decades. It is, however, a prerequisite for making that the "default for everyone, in a way that's difficult to mess up". Password managers are not and cannot be the default for everyone, because it's easier to just reuse use the same weak password everywhere so long as that remains an option. Until that changes, insecure password management practices will be widespread. > The first step towards that is designing a system that is simple in its architecture. Simplicity of the architecture is mostly irrelevant, simplicity of usage is what matters. I agree teaching users how to manually manage X.509 certificates would not be viable, but I don't think anyone is arguing for that.
- usrbinbash 5y ago> so long as that remains an option. This will remain an option. Probably forever. The reason is simple; comfort is a selling point. And everything requires more energy to set up than chosing a plain old password. Sure, security is a selling point as well, but its really hard to argue that to consumers, when security comes at a comfort-cost. So in my opinion, if, passwords are here to stay anyway, we should explore avenues to, on average, make them stronger and get people to use unique ones for their services with as litte impact to comfort as possible. Password managers are a very good step in that direction.
- Ajedi32 5y ago> And everything requires more energy to set up than choosing a plain old password That's only true so long as there's no mainstream alternative. If everyone needs to have WebAuthn set up anyway for some other service they're using that doesn't use passwords, then the marginal "comfort-cost" of adding another account to system will be even lower than the cost of signing up with a password. (Choose a password? Or just click the "use WebAuthn" button?)
- usrbinbash 5y ago> If everyone needs to have WebAuthn set up anyway for some other service they're using that doesn't use passwords That service will have to explain to its customers why they need to get/install/configure a WebAuthn Authenticator (which includes taking care of another device / another piece of software), when their direct competitors allow users to log in with just a plain old password. Said explanation doesn't just have to convince the average customer used to passwords, it also has to convince people like me, who use password credentials in a highly secure and reliable way. They will also have to explain why if, eg. the USB connector gets damaged (in the case of a hw-authenticator) because it has been stored in the users pockets with a bunch of keys and thigh-sweat, they suddenly can't access their emails any more. WebAuthn has been around for almost 8 years now (published May 2016). Big Players enthusiastically support it. And still all major services allow login via password credentials.
- Ajedi32 5y agoWebAuthn does not require a USB device. For the first few sites that deprecate passwords the explanation will be something like "we have strict security requirements, passwords are not secure, we're getting rid of them". Once that becomes the norm for high-security applications other sites will follow, since they won't have to deal with the initial barrier of getting users to set up WebAuthn. > WebAuthn has been around for almost 8 years now (published May 2016). Big Players enthusiastically support it. They enthusiastically support it for 2FA. I haven't seen any concerted effort yet to use WebAuthn as a password replacement, or to implement any of the basic features that would make that viable (like synced credentials). I find that very disappointing, as we could have been well on our way to phasing out passwords already if the big players in the space had started this 4 years ago back when the WebAuthn spec was finalized.