5 ms·
A flow can either fail safe or fail secure. Fail secure: if you lose your email, your account is forever locked. Fail safe: if you lose your email, your accou
by pocksuppet 4mo ago
A flow can either fail safe or fail secure.
Fail secure: if you lose your email, your account is forever locked.
Fail safe: if you lose your email, your account is not forever locked. But, someone else might be able to get your account by pretending you lost your email.
There are no other choices.
When the electronic door controller loses power, either the door stays locked, or the door stays unlocked. In case of a fire you want it unlocked so people can get out. But then a burglar can cut the power to get in. Doors that stay permanently locked in a power outage are only permitted in extreme cases where security is of the utmost importance. Obviously Instagram accounts aren't as important as doors in a fire.
- eddd-ddde 4mo agoWhat about "go see an agent in person and use your fingerprint to prove it is you"?
- deleted 4mo ago[deleted]
- HDBaseT 4mo agoI don't think its that binary. Using the door and fire scenario, you can have manual opening method available, just make it only available on the inside.
- Lonestar1440 4mo agoThere are no other online choices. If my Bank login goes totally Kaput, though, I can take my ID down to the Branch to get it sorted. Same with my telecom provider. I try to only depend on services which have this property. I don't succeed.
- ipaddr 4mo agoSounds great until you have an aging parent with a problem who can't get there. Get a power of attorney you say.. great but they won't accept unless parent comes to the branch. This comes back to haunt you in the future.
- Lonestar1440 4mo agoI've done this. I'm very surprised that, in your case, the POA was not sufficient to get your business done. I'm not sure what alternative you are proposing. This only gets much, much worse when the aging person is trying to use a password...
- ajsnigrutin 4mo agoOn the other hand, the best anti-scam feature for older relatives is to tell them to "go there in person". Get a call from the bank, they simply tell them "ok, I'm coming to the bank tomorrow, in person", and they're done. Scam call? Legit call? Doesn't matter, they'll sort it out at the bank. There's a whole wide age and knowledge/competence where older people can still fall for scams (or can't know if it's legit or a scam) but on the other hand are still capable to go to whatever office/bank they need to go.
- Terr_ 4mo agoProbably not news to anyone here, but partial step in this direction is to put down vetted official contact details for the institutions. Every time someone calls to say there's a problem with your account, you ask for their name and/or extension number, because recontacting through the institution is your only good way of verifying their identity.
- kijin 4mo agoMalware on your phone can reroute your calls to the attacker. So you think you're calling the official number at the correct institution, but you're actually talking to the attacker.
- Terr_ 4mo agoWell, yeah, and knowing first-aid is worthless if someone's been decapitated. :p If some malware is that deep on the phone, able to redirect calls, then you've got much bigger problems and the attacker might not even need to trick any cooperation at all.
- gamerDude 4mo agoSeems like a business opportunity. Face to face authentication in every major city that can authenticate people when needed.
- bandrami 4mo agoThis is actually one of the more useful services those horrible check-cashing storefronts provide.
- dzhiurgis 4mo agoTake it to the branch? Like in the 90s? What?
- foxglacier 4mo agoTech people forget how the real world has solved these problems long ago. I got access to my bank account in another country by writing them a letter on paper and having it signed by a policeman in my country then sending it in the mail. A pain and expensive but if it's important, you do it. All these old fashioned techniques are backed by the criminal justice system which can actually work when the fraudsters have to go to the police station to commit their crime.
- CPLX 4mo agoOf course it's not binary, any more than there are two choices between "cheap" and "expensive" The question is how much effort and authority is required to gain access through alternative means, not whether it's possible. It's always a question of how much, insofar as kidnapping Mark Zuckerberg or winning an order from a Federal Judge are two of the possible scenarios.
- hijodelsol 4mo agoThere are definitely more shades of grey. On my iPhone I can select a close contact to be able to overturn my protection but this contact needs to have security features turned on, too. So Apple staff cannot do it, only a non publicly known person that has 2FA and encryption themselves. Add time delays, notifications, identity checks and more to it and you can make this process reasonably secure while still ensuring recovery.
- deleted 4mo ago[deleted]
- dgacmu 4mo agoI'm probably out of date, but Google's advanced protection at one point did account recovery via postcard to your home address. High latency but pretty good as a fallback.
- HWR_14 4mo agoPostcards are the least secure form of mail. I would hope it uses a security envelope at least.
- itintheory 4mo agoThere are many good options. [1] [1] https://news.ycombinator.com/item?id=48321089 https://news.ycombinator.com/item?id=48321089
- cortesoft 4mo agoThere are a lot of other ways they could do it. You could provide a delay feature… if you request this sort of reset, it takes 3 days, and emails are sent to the primary address every day with the count down. If your email isn’t lost, you would see these warnings. You could let an account holder designate emergency contacts (other accounts) that are allowed to request a reset if you lose your primary email (again with a time delay to allow you to block malicious takeover attempts). Recovery keys, security questions, real life identity proof, etc, are all other possible options, too.
- markdown 4mo ago1. Provide a delay of a week. 2. Notify via all addresses on file. 3. Make an admin post (by the account in question) explaining that a 2FA override has been requested. Something you and all your followers can see.
- aryan14 4mo agoThis is actually what microsoft does for microsoft accounts If you recover a microsoft account / submit a ticket to recover it and provide correct information, the active email gets an email letting them know about the request You can deny it, or if you ignore it for 30 days the request goes through Seems to be the best system IMO
- faidit 4mo agoSomeone has been trying to hack into my MSFT account for years. I constantly get the notifications. I can not see where they are trying from (unlike some other services that give you info about failed login attempts) nor add more security measures. I worry one day I will accidentally hit "Approve" or they will guess the 6 digit code they have tried thousands of times. The fun part is that you can't disable OneDrive. No matter how many times I turn it off it always keeps turning OneDrive back on to put my private data in the cloud for the attackers. Of course I can't block the methods that are obviously under attack either. And the lack of a login history view means I have no way to know if they were successful yet. Support has never been good (for legitimate users) and is basically non-existent with AI now.
- subscribed 4mo agoThere's also Google fail. You have everything (including recovery emails) except the phone you had 15 years ago, and you lose your account.
- wwn_se 4mo agoThere is a third option. Most banks here in Sweden solve this by forcing you to show up in person (with a ID card) if you loose your password. I get that this also is technically a 2FA bypass but the cost is extreme and its really hard to impersonate someone in real life.
- sigmoid10 4mo agoHow would that even work for internet companies without physical stores? Go to Menlo Park, CA to recover your account?
- stoltzmann 4mo agoFacebook already requires verifying your ID in some cases, it's absolutely feasible for them to do it online. If it's not feasible, I can see an argument that large enough companies should be required to provide in person support options. Facebook defintely has enough money to facilitate this.
- wasmitnetzen 4mo agoThere's a lot of online-only banks who have figured this out. Do video auth, outsource it to the postal service, ...
- vkou 4mo agoA compromise solution would be to fail safe with a cook-off period and a notification for any active users. It would mean that someone can't gank an account from under you while you're using it, but you could recover it after a week if you lose access to your email.
- anilakar 4mo ago> There are no other choices. Fail safe noisily and implement a cooldown period.
- throwaway173738 4mo agoThis is too simplistic. A lot of automatic door locks are just door strikes with a solenoid that is remotely actuated inside the door casing. In that model you can let people out of the building because the inner part of the door has a bar you can press that moves the door pin, which is how all door handles work normally, so there’s no “fail open” needed. You can get out, but you might not be able to get back in.