4 ms·
I was about to post this, thank you for doing so. Seriously? What could they be thinking? The entire premise of 2-factor - in most cases, something you know an
by deitcher 12y ago
I was about to post this, thank you for doing so.
Seriously? What could they be thinking? The entire premise of 2-factor - in most cases, something you know and something you have - is that if someone steals/guesses/social hacks my secret, they don't have my keyfob (or phone); if someone steals my keyfob or phone, they don't have my secret knowledge. The probability of losing both is much lower than either.
But using just one factor, and one that goes across insecure networks, and is visible on my phone even on the lock screen? And I cannot use it if I have mobile issues? Really??
- deleted 12y ago[deleted]
- higherpurpose 12y agoExcept this basically leaves the passwords in the hands of the companies. It's like Yahoo saying "you don't need a password anymore, we'll just create one on the spot for you". That's not what I imagined for a passwordless world. I don't want the companies to basically keep the passwords for me. I'd much rather put my trust in fingerprint scanners or other biometrics.
- count 12y agoYou can't change biometrics, ever. You can spoof them, same as a text password can be cracked. They're HORRIBLE factors.
- deitcher 12y agoThey won't even need to bother. State-level actors usually have access to the phone company networks.
- deitcher 12y agoI said I would write it up. I love the title: "Yahoo's On-Demand (In)Security." http://blog.atomicinc.com/2015/03/16/yahoos-on-demand-insecurity-2401/ http://blog.atomicinc.com/2015/03/16/yahoos-on-demand-insecu... I should submit it directly to HN...
- mcherm 12y agoTwo-factor authentication is far superior. But I might be willing to concede that one factor authentication (using something you have) is about as good as one factor authentication (using something you know). Especially since password guessing is at or better than actual practice by real humans in password selection and security.
- VLM 12y agoPerhaps the other factor of 2FA is rather optimistically your yahoo username. Somebody online would know my yahoo id, but only a microscopic fraction of online people would have physical access to steal my phone. Someone who steals my phone would almost certainly have no idea what my yahoo login name is. I would have to look it up myself just to make sure... The intersection would be close friends and family members, and if I can't trust them, then I'm totally screwed aside from mere yahoo groups login issues.
- deitcher 12y agoIf Yahoo really thinks that, they have issues with security... oh wait, they do! :-)