7 ms·
I simply won’t use any service that requires a phone and doesn’t allow other options. I am opposed to a future in which phones are a necessity of life rather th
by Jimmy 4y ago
I simply won’t use any service that requires a phone and doesn’t allow other options. I am opposed to a future in which phones are a necessity of life rather than merely a convenience.
And to the people who say “but desktops/laptops are already a necessity of life” - yes, and that’s a problem. We need to be actively thinking of ways to roll things back, rather than allowing technology to become more and more integrated into life.
- tjr225 4y agoWhat if I lose my phone or forget it at home? Can I no longer do my personal banking on my laptop or workstation?
- ghaff 4y agoThat's true today if you use a password manager, no? And it's true of any site that uses 2FA (unless the site supports multiple authenticators and you have a backup token).
- xyzzy_plugh 4y agoMy password manager is accessible on my other computers, so no it's not true today.
- bartchamdo 4y agoThe better analogy if your driver’s license/ID it passport. If you leave these, you likely can’t travel or be admitted into specific establishments, etc.
- ghaff 4y agoEver since I somehow managed to lose my driver's license between the private car that dropped me off at the airport and the door to the airport, I always use another government ID I don't actually need for anything (Global Entry) while going through security. I also usually carry my passport as a backup though that probably won't work if I need to rent car--and on that particular trip it was a last minute overnighter so I didn't throw in my backup documents and cards folder. It took me about half an hour to convince the hotel to let me check in. In general, I hate traveling with things that you really can't afford to lose and can only mitigate against loss to some degree.
- e2le 4y ago> In general, I hate traveling with things that you really can't afford to lose and can only mitigate against loss to some degree. This could be resolved using a FIDO enabled NFC sub-dermal implant.
- Wowfunhappy 4y agoSo now I'm modifying my body in order to use the internet?
- e2le 4y agoWhy not? If they're made cheap enough for everyone to use, it provides greater security over other methods.
- BiteCode_dev 4y agoIdentification systems on computers are already abused to extremes. There is no way a putting a identifiction system inside your body is not going to result in tremendous abuses on the long run, with much more terrible social consequences since it will be linked to individuals and hard to disable or remove. The simple fact there no guaranty of safety that can be made about such a system despite its obvious consequences about tracking, power and control should alone be a red flag. When I read such a comment, I can't help but think school should make kids read more science fiction. Many authors covered why something like this is a dangerous idea. I'd go even farther, but I would reach the Goodwin point.
- Wowfunhappy 4y agoBut it's always possible to get a new passport, even if you've lost every other type of identification. What happens if I loose my Yubikey and all of my backup codes?
- ghaff 4y agoAs noted in the article, it's a tough problem. The easier you make account recovery the easier you make attacking those recovery methods.
- Wowfunhappy 4y agoIt so happens that I have a great solution to this tough problem, which has served me well for years. I have a password manager, protected by a strong, unique, randomly-generated master password that I took the time to commit to memory. I cannot ever loose this password, and as long as I have it, I can get into my vault. As long as I can get into my vault, I have access to my other passwords. An increasing number of web services have decided this is insecure, and are forcing me to use secondary devices in order to authenticate myself. This does very little to increase my security, while putting me at risk of getting locked out of essential resources. I'm all for alternate options, but please don't take this setup away from me!
- ghaff 4y agoDesktops/laptops aren't a necessity of life for many people. In general, I'd say smartphones were a far more universal necessity today.
- Jimmy 4y agoSorry, that may have been poorly worded. I wanted to preempt the objection of “well, you say you don’t want to be dependent on smartphones, but then you’ll just be dependent on some other type of computer”. I wanted to make it clear that the problem is about rethinking our relationship with computing in general, not just with smartphones.
- roywashere 4y agoThe article does not fully explain it, but the proposal is about using FIDO to sign in to services. The article simplifies this as signing in by unlocking your phone, but that is just one way to do FIDO (and possibly the most common way). If you prefer not to use your phone, you can also use a YubiKey or similar on your desktop/laptop; pushing FIDO as a standard would probably make it possible to use a YubiKey with much more services than today!
- autoexec 4y agoFIDO weakens security by limiting authentication to just something you have (a device/USB token) and something you are (biometrics) while throwing out the requirement for something you know (a password). Something you have can be easily stolen, and biometrics cannot be kept secret, can be forged, and can't be reset/changed once compromised. Having something you know (a password) is more secure because something in your memory that you don't share can't be taken from you by any means. Passwords aren't perfect (you can be tricked into sharing it, or tortured into giving it up) but there are solutions for being forced to hand over a password, and neither tokens or biometrics solve the problem of people being tricked. No one can murder you in an alley, and drag your lifeless corpse to an ATM and clean out your bank account because the murderers have your face, and fingerprints, even your cell phone, but not your pin. Good security should always require a secret that you know. Not having a password would be fine for logging into low risk sites like this website, where at worst someone might get your account banned or post comments under your username, but any site or transaction where the risk is greater should just always require a password.
- jjulius 4y agoPreface: I've been busy as shit this week and haven't really read up on FIDO. I don't know that I have a position on it yet. > Something you have can be easily stolen, and biometrics cannot be kept secret, can be forged, and can't be reset/changed once compromised. Something you have can easily be stolen as long as someone is able to access it. Someone on the other side of the world is not going to be able to steal your USB token from the comfort of their own bedroom, just as they're unlikely to get your biometrics. A password exists in your memory, yes, but it also exists in the databases of untold numbers of corporations, each with different levels of security, and at least some of those corporations duplicate copies of those databases across different data centers throughout the world. These databases can essentially be accessed by anyone, anywhere. I understand what you're saying, but you're forgetting that passwords, by nature, have to exist somewhere other than your head, guarded by someone other than you.
- mistrial9 4y agostrongly agree
- Wowfunhappy 4y ago> “but desktops/laptops are already a necessity of life” No they're not! You need either a desktop or a laptop or a tablet or a smartphone, but you don't need more than one. I'm okay living in a world where everyone needs access to some type of computer, in the same way that everyone probably needs access to some type of writing utensil. However, people should be able to choose the form factor that lets them live their best life.
- Teever 4y ago> However, people should be able to choose the form factor that lets them live their best life. Especially when one particular form factor leads to surveillance of your location.
- theamk 4y agoI assume you mean phones? This is not a form factor result, it's a result of a function. If you want to have internet access without being near internet AP, you have to accept surveillance. This applies equally to phone, or tablet with SIM card, or laptop with external 3G modem. If you are OK with only accessing internet in specific location, you can turn off cell subsystem in your phone -- this functionality is present in every phone I have seen. (Same applies to bluetooth, wifi and other ways to track device remotely)
- spaniard89277 4y agoMobile phones could be open systems like PCs are. But they aren't. So we should oppose this movement to use phones for everything until the situation changes. Not to mention that old people is suffering (at least here in Spain) a lot because services push everyone into apps etc. I cancelled my fathers bank account for this very reason and moved him to a credit union. It was painful but their customer support was so awful that it was worth it. The last straw was that they told him he couldn't do a money transfer from his local office but he had to use a mobile app. He called me to help him with that. That got me angry.
- Wowfunhappy 4y ago
- 650REDHAIR 4y agoI’ve been thinking about going phoneless, but had a realization that I have used this number for far too many accounts to even remember. I basically need to port this number to a cheaper carrier and cover the cost…forever
- drewmol 4y agoYou can port to google voice for cheap, but you definitely can’t count on google offering that service forever.
- 650REDHAIR 4y agoBig G has burned me too many times! I have a vanity number or 2 through them and that is stressful enough!
- idle_zealot 4y agoI strongly disagree. Personal computers are here to stay, and will only become more integrated into daily life due to the conveniences they afford. The fight now isn’t to keep computing out of daily life. Rather, we ought to be fighting to ensure that people have control over the computers in their lives. There are two ways this ends up: The future where everyone has to carry around a black box computing device controlled by its manufacturer and the privileged creators of the apps you’ve been allowed or compelled to install on it. The present state of iPads/iPhones and to a lesser extent Android phones make this future feel incredibly close. But the future where everyone carries around an incredible communication and calculation tool that acts as an agent for them and expands every individual’s capabilities feels only just slightly out of reach. The line dividing the two futures is thin and technical in nature. This leaves us with a tricky situation where most people wouldn’t be able to distinguish which they’re headed towards, or even which they’re living in. All I can do is hope that either legal tides go my way and grant users control over their computers (phones) by force, or that somehow tech literacy rises and people demand control.
- OJFord 4y agoI think you need to define personal compute as including mobile phones/tables for that to be true. I've had several even highly technical colleagues with no non-work 'computer' - they use an iPad or whatever, because that's sufficient for their non-work use of one.
- idle_zealot 4y agoI didn’t realize that my usage if the term was unclear, but to clarify: an iPad is a personal computer. A smartphone is a personal computer. Even modern game consoles are personal computers. They’re all general-purpose computers owned by an individual. However, they have software locks placed on them that prevent their owners from controlling them. In the post above when I’m talking about personal computers that we carry around I primarily mean phones. I will update the post to clarify.
- Jimmy 4y agoI don’t really disagree. I’m not a luddite and I don’t advocate for turning off the internet. Computers are certainly here to stay. It’s an extremely complex issue, and I don’t have all the answers, or even know how to phrase all the questions. I do think society needs to take a proactive role in deciding how it wants to interact with technology though. There’s a certain laissez faire, almost defeatist attitude that you see from a lot of the tech crowd, that goes something like “technology will do what it does, and it will change our lives how it sees fit, and we are powerless to stop it.” But if that was the case, we couldn’t have gun control laws, or environmental protection laws, or restrictions on nuclear technology. Technology may continue to develop, but it’s still up to us how we choose to use it.
- TedDoesntTalk 4y ago> We need to be actively thinking of ways to roll things back Although I agree with you, it is not realistic. Do you think kids who are 3 right now will feel the same when they are your age? Reminds me of the US General who, in WW II, insisted cavalry still had a place in warfare. Can’t remember his name.
- xdennis 4y ago> Reminds me of the US General who, in WW II, insisted cavalry still had a place in warfare. Can’t remember his name. Cavalry still had a huge role to play in WW2. You didn't ride them into battle (you didn't do that in WW1 either), but they were used for transport. Germany and Russia used 6 million of them.[1] [1]: https://en.wikipedia.org/wiki/Horses_in_World_War_II https://en.wikipedia.org/wiki/Horses_in_World_War_II
- TedDoesntTalk 4y agoCalvary != Horses It was Maj Gen John Herr: 1 point by TedDoesntTalk 7 minutes ago | root | parent | next | edit | delete [–] It was Maj Gen John Herr: "In 1945 Herr wrote that conversion of cavalry to armor was a mistake, an act of "robbing Peter to pay Paul": expansion of armor was necessary, but not at the expense of horse units." https://en.wikipedia.org/wiki/John_Knowles_Herr#Chief_of_Cavalry https://en.wikipedia.org/wiki/John_Knowles_Herr#Chief_of_Cav...
- peoplefromibiza 4y agoThe 10th Mountain Cavalry Reconnaissance Troop of the 10th Mountain Division, while not designated as U.S. Cavalry, conducted the last horse-mounted charge of any Army organization while engaged in Austria in 1945. An impromptu pistol charge by the Third Platoon was carried out when the Troop encountered a machine gun nest in an Italian village/town sometime between 14–23 April 1945. anyway the point is not to go back to soldiers riding horses, but to not reduce the authentication options, because it also reduces security. After all we still use keys to unlock doors and not our phones (because it would be stupid)
- 4y ago
- la6472 4y agoFirst thing that comes to my mind is “What happens if your phone is suddenly dead”? Will this FIDO alliance guarantee alternative means of access or that they will send someone down to your house to identify you positively and restore access to your online mail and documents?
- dandanua 4y agoThe problem is not with the technology itself. The problem is that technology is increasingly trying to control you and not vice versa. Humans are becoming slaves of a system, that has only "profits" in its mind.