3 ms·
No, passwords on their own are never "enough" for you to be secure as you only control your side of the equation. You don't know if the place you are storing it
by LocalPCGuy 4y ago
No, passwords on their own are never "enough" for you to be secure as you only control your side of the equation. You don't know if the place you are storing it is doing so in plain text, storing a decryption key right next to it, etc. Even if you are careful (I know what you said above), the network you are on could be compromised despite your best efforts/knowledge. Or any number of other things that could make it trivial for someone to gain access to your account in the event they gain access to simply the password.
I don't claim 2FA is perfect, it has its own host of issues as is being discussed. But it isn't just for "the masses that don't understand how to make strong passwords or how to be secure". Certs are good, but they need to be made simpler than they are now for the very people you claim 2FA is for or they won't be adopted (one of the reasons they aren't more ubiquitous, IMO). And some certs implementations have issues with account recovery as well if you lose access to them.
It's a really hard problem that you do a bit of disservice to when you dismiss it as "just a problem of the plebes".
- envy2 4y ago> You don't know if the place you are storing it is doing so in plain text, storing a decryption key right next to it, etc. Any service that is storing passwords in plain text is probably not implementing 2FA in an safe way, either.
- LocalPCGuy 4y agoThat really isn't an argument against my point, that it's very hard to verify what is happening once you click submit with your password.
- TedDoesntTalk 4y agoPassword-only authentication still has its uses. I don’t want to use 2FA when I’m logging into a website I’ll use once and never again and does not have any private info about me, maybe to post a comment for example. Or try a service they are demoing.
- Vladimof 4y agoIm glad news.yc and reddit don't require email to sign up...
- LocalPCGuy 4y agoThose are totally valid use cases. In no way was I saying everything had to offer 2FA. Just pointing out that it is not just for those that don't know how to craft strong passwords or those that practice poor security hygiene, that it is a useful option to have when security is important.