5 ms·
The new Hell I'm experiencing is everyone wanting to validate my identity through my phone. Email does it, banking does it, I suspect by the end of the year Win
by aimor 4y ago
The new Hell I'm experiencing is everyone wanting to validate my identity through my phone. Email does it, banking does it, I suspect by the end of the year Windows will probably be sending me a code before I can log in. I'm sick of it. I don't like needing to have my phone on me, I don't like the fear that if I lose my phone I'll be locked out of everything, and I really don't like being forced into this.
It feels like there's a lot of fear around passwords right now. I'm sure companies see them as a liability and are eager to move away from them as soon as possible. Are we going to have a future where each person (or identity) has a single hardware token for all logins? I don't think we're anywhere close to that yet.
- wetpaws 4y agoI switched to Google Voice after changing my phone number a couple of times and going through the 2fa replacement hell.
- rexf 4y agoI use GV, but it's really tough to use with many sites. Many sites will detect the non-cellphone (virtual) nature of the number and require a different (cellphone backed) number. Yesterday, I put my GV number in the DALL·E sign up and it wouldn't let me proceed. So I abandoned the sign up flow.
- avree 4y agoMost 2fa platforms detect and block GV (and similar VOIP numbers)
- plaguepilled 4y agoSMS TOTP is indeed bad and your suspicion is well warranted. Its a lazy way to implement 2-factor authentication and exposes the user to MITM attacks as well as a host of other nastiness. U2F (stuff like what Google Authenticator does) is way better and less phone dependent. The only reason a team would opt for TOTP if they had the resources to implement U2F is because its a good way to get your phone number. Edit: embarrassingly I've made an error in my use of acronyms. What I refer to as TOTP is in fact plaintext OTP sent via SMS, and what I refer to as U2F is actually app-based TOTP. Apologies!
- olliej 4y agoI disagree here, suspicion is not warranted - I'd prefer that they support additional non-sms 2FA paths, but supporting SMS based 2FA has many benefits for a company beyond being "lazy" SMS is vastly better than nothing, and it has the benefit of not requiring users install random software that they (a) don't know how to install, (b) don't know how to use, (c) don't have a recent enough device to use, (d) you don't need to worry about them deleting the app and then losing their 2f, (e) doesn't require your customers having an account with (and potentially paying) another company just to log in to your site, etc I really do think that tech people over estimate the proportion of people for whom at least one of the above applies. Not everyone runs a one or two year old phone, many of the very cheap phones run very old versions of android, can't be updated, etc Obviously SMS 2FA has a different problem as the sufficiently poor may not have a constant phone number, obviously sim hijacks can happen but the targeting requires much more effort than simply moving on to the next non-2fa account. [edit: updated to make sentence structure not look like a series of wordle guesses]
- nl 4y agoTOTP should run on any smartphone, including phones that are much older than 2 years.
- olliej 4y agoHuh, you're correct those apps have much longer support than I expected - but did not check :( - from free apps (though I guess Google Authenticator is backed a small immigrant business :D ), thanks for pointing out my error, I'd fix my comment but can no longer edit things. What I was trying to say there are a _lot_ of very old smart phones in poor communities, and they're still in use. I searched craigslist in very poor parts of the US and I can find quite a few phones that are running android <= 4, and have fingerprints implying they were in use. I would guess that that end of the spectrum has many more offline only transactions. It's also a community who may not have internet access, and may not have library access, which is how people in larger cities can access the internet (from volunteering I discovered sometimes to watch porn :-/). Not intended as a correction to your comment, but just as a backup for my statement that plenty of phones still can't use TOTP apps, the cheapest phones with t-mobile are not smartphones, and the cheapest ones on amazon are not running a recent enough android, and some even run Windows OS?!?!?!
- m8s 4y agoI recently had to tell my bank, with my voice over the phone, that the make and model of my first car were the three random words 1Password generated for me. “Yes, the make and model of my first car was… a Venerated Breakfast Platoon.”
- aaronbrethorst 4y agoI hope you either made up that code or changed it after posting this.
- m8s 4y agoThat was obviously not the actual code :)
- popcorncowboy 4y agoLittle-to-nothing to do with liability. Your identity = $. Phone-validated users are simply higher ARPU and (somewhat less importantly) lower risk - an artefact of gating access behind harder-to-spoof touch points. To the extent that a hardware token proffers anon/pseudonymous verification, there'll be pushback from industry. Because again, your identity = $. Expect anything that would plausibly get a revenue bump from verifying identity to force you to do so eventually. Because you know, security.
- Double_a_92 4y agoTo be fair my phone is probably the safest device I own. If I had do to 2FA that's where I would want to receive it, locked behind my fingerprint...