User rant: I hate where this new Internet is going. Instead of having a username and a few secure hardware tokens that I can use to log in from any internet cafe [1] on the planet, I am now subjected to a barrage of suspicious "Is this you? Is this really you? Are you sure this is you?" inquiries every time I so much as take a trip out of state. It seems like the next step will be a requirement to show a Government ID every time I access the Internet from outside my house.
"Passwords are insecure" is not a good enough rebuttal to this, honestly. We have far more robust authentication methods available; and it's possible to make them standard and avoid this "Remember me" nonsense. Instead, we get all of it for what seems to be the sole purpose of even more user tracking.
"Is this you?" mode is (now) called Risk-based Authentication [1] [2] [3], although it's been around in various forms for over 15 years. It's an important part of defense-in-depth for user-facing application security. Without it, it would be much easier to attack the vast majority of user accounts, because most people are not as secure as you might be, and authentication methods and strengths/weaknesses vary.
HN tends to completely ignore all of the real problems these solutions solve. They live in some fantasy land where organised cybercrime isn’t crippling the lives of thousands daily.
Well I think we should consider their experience is different. Many live in either the startup-land where attacks are rare and trivial, or in user-land where the attacks are just in the news, not affecting them. They don't see the daily nation-state attacks, massive botnet operations, spear-phishing campaigns, persistent multi-vector campaigns, ransomware, illicit mining operations, Amazon-laundered cybercrime. They just assume that nobody wants to hack them, so why does security need to be so difficult? And companies don't do a good job of telling people what kind of risks they are shutting down because it would scare the fuck out of people.
The problem is that the barrage of "Is this really you?" checks desensitises people to putting in passwords, 2FA tokens, clicking on captchas and other such things.
Most people on HN are American so have no direct experience or knowledge of terrorism, but in the UK a favourite trick of Republican terrorists was to call in hoax bomb threat after hoax bomb threat, causing massive disruption with maybe only one or two real devices for every dozen or so incidents. People got a bit blasé about it, so when the real attacks happened they were much worse than they would otherwise have been.
If you continually blast users with "OMG CRIMINALS MIGHT BE STEALING YOUR DATA CLICK HERE TO STOP THEM" then you're just priming them to be a big fat source of information when a suitably-crafted attack site pops up its message.
I agree that's a problem. But as long as I've been around, theres' always been a fine line between usability and security. You introduce one change to fix one problem and it creates another. You try to simplify and end up over-simplifying. You give users more control and they choose convenience over security, which for a very large population or critical infrastructure has larger ripple effects (every compromise is a foothold into another compromise). There are other solutions, like FIDO2 with a hardware token and approval button, but that has its own drawbacks and adoption is slow. Every solution is kinda sucky :(
Agreed, but to add a little more nuance to it; we live in tech-land, which we would _like_to be separate from mass-adoption-land. The lowest common denominator ruins it increasingly more, the further away (up) you go.
This is why we see things like Gemini popping up. It's an attempt to set the bar at "do you _really_ want in on this, even though it doesn't have pretty flashing pictures and the toktiks?".
I'm not judging either way, but I sure did like it before the web got utility status.
Security is the kind of thing where it doesn’t matter up until it really matters.
So you can complain about Google applying additional security but when the obscure npm package you installed steals your passwords and google blocks the login because it was from a known bad IP in Russia, you’ll be thankful it exists.
Doubt many Gemini sites are using Node.js on the backend, obscure packages or otherwise.
Also given that installing npms willy-nilly is your go-to example for security risk, maybe that should have a hasslewall around it instead of username:password authentication:
"You are attempting to install a node package for trivially-implemented behavior. To prove your computer-literacy, enter a javascript function that accepts a string as an argument and returns only the characters with prime-numbered indices."
For what it's worth, I explicitly designated the original post as a user rant. I am accurately playing a user by not caring about all the "real problems" these solutions solve. If I'm continually locked out of my devices and websites just because I'm traveling, that causes genuine inconvenience to me.
Ironically, by painting your users as "living in a fantasy land" rather than "focusing on their own business, which doesn't involve taking down large-scale cybercrime", you're the one being unrealistic. A normal user does not know or care what large-scale problems can be solved by the inconvenience they are currently facing.
What I hate the most about this is that “is this you” is triggered apparently on a browser version change, which can be up to two times a week.
On top of that, with apple private relay, an iPhone’s IP address changes quite frequently.
Another guilty site is Amazon. As long as you want to buy another phone, they are OK with your session, but if you want to check your order history, suddenly they are not so sure about your identity — no investigate, only buy…
Thanks to lovely "2FA" methods (more likely RFA) like described here, I am currently locked out of my 15+ year old Google account that I no longer use, as they require me to provide them a verification code from an old Android phone I sold over 5 years ago. I contacted Google support - they can't do nothing, even though I could provide every single piece of data about the account imaginable - including stuff like the IP ranges that the account was accessed from most of the time, devices linked etc. - sadly, I suspect no real human sits in front of their support chat...
I was locked out of my 10+ year old google account for daring to use IMAP to access gmail from unknown networks and ignoring the "is this you?" emails for a while. I'd all but given up on it until I got a brand new Pixel a couple years back, I figured I'd try logging in with the last password I remembered working and it just worked, no complaints from the RFA. I guess the RFA requirements are completely dropped when logging in from a new phone to avoid people getting locked out as they're setting up their phone.
You're not thinking long-tail enough. Once a service reaches a certain size you have to deal with every single kind of failure.
* User forgot their password.
* User's authentication token was eaten by an alligator.
* User's phone fell down a well.
* User's phone broke and they got a new number from their carrier.
* User's phone, laptop, and hardware token were lost by an airline.
* User's phone and backup codes were simultaneously lost in a fire.
* For Google specifically, user lost access to their email and didn't have a recovery set up.
If you can reasonably authenticate them using any means you probably should let them because every time you have to fall back to human customer support it's $$$. Remembering a password is one of the few things that's resistant to life's bullshit but it's also incredibly insecure so this is the compromise.
> User's authentication token was eaten by an alligator.
> User's phone, laptop, and hardware token were lost by an airline.
> User's phone and backup codes were simultaneously lost in a fire.
There should be a recovery process. However, the recovery process should be tedious and thorough enough to reliably authenticate the user and not be vulnerable to attacks. Charge a cost for the recovery process.
> because every time you have to fall back to human customer support it's $$$
Sometimes, "fuck off" can be the right answer, especially when the downside is a vulnerability that ends up costing more in fraud/reputation/legal liabilities.
House doors don't (yet?) come with a "forgot your key?" button, and the world hasn't ended, so it seems like most people are able to keep track of physical keys and have no problem paying a locksmith to break & replace the locks if needed. Safes don't come with those buttons either, and yet safe manufacturers haven't gone out of business because it takes significant cost, time & effort to open one if you lost the key (that's the whole point of it).
> House doors don't (yet?) come with a "forgot your key?" button.
Welp, I do this. I'm incredibly forgetful, adhd is a bitch, so I have a spare key in a lockbox by the door that takes a combination and give copies of my keys to my friends. And I have the combination in my password manager so even if I forget both but have my phone I'm still good. I also keep multiple copies of my credit cards and driver's license. This stuff has saved me literally hundreds of times.
I'm not sure I understand the logic of not letting someone authenticate themselves with the
A recovery process that costs $10 and actually works is great value. Assuming the recovery is for credentials that the user lost (and not Google deciding to lock them out for no reason), it seems totally fair - after all, you don't expect a locksmith to replace your locks for free either.
I suppose, but if I already entered the code from my authenticator app is having me click on an email going to make it more secure? If they have my authenticator app then they've already totally owned me anyway.
Sending an email as a notification would serve the same purpose.
> is having me click on an email going to make it more secure?
We implemented this at Mercury recently to stop phishing attacks, and I believe Coinbase implemented it for the same reason [1].
TOTP authenticators are super ineffective at combating phishing. If a user is willing to give their email and password to a phishing site, there's very little standing in the way of them also providing their TOTP code.
WebAuthn solves this by working with the browser to tie authentication to a particular domain, but not everyone has a WebAuthn authenticator yet.
Meanwhile, email verification links are a really simple and effective way to shut down these phishing attacks. The phisher can't click the links, because they don't have access to the user's email. The user can't click the links on behalf of the phisher, because clicking the link only verifies the device that clicks the link.
Oh, I hadn't read that as merely having the e-mail address and password to the site, but having the password to the e-mail account. I get it now. Though, it still irks me that we are now up to 3 factor authentication--password, TOTP, and e-mail--under the premise that the user is too dumb to secure 2 factors, and yet somehow is smart enough to secure the third one.
One aspect we're not thinking about is the customer service cost to a world without passwords. If you forget your password, they just email you a new one. What happens if you lose your bank's 2FA token and miss a payment deadline? "Too bad so sad," is the HN answer, but customers will move their money elsewhere. So now you need a budget for a call center, replacing hardware tokens with overnight shipping, and the "oops we'll pay the late fee for you", at least in the early days. (Once it's "normal" then those benefits will go away, but who is going to keep their money in a bank where they need to carry around something on their keychain, and if they lose it, they lose all their money? Nobody. You have to really smooth over the jarring transition, and that's expensive.)
Meanwhile "are you sure it's you?" questions are free; pay a software engineer to write them, never touch it again, no matter how many customers you have.
So I guess the question you have to answer, is how can a company make more money off of you by changing how you authenticate? If you show them the $$, they'll show you the WebAuthn.
Why does everyone jump to banks? They are welcome to keep their annoying security procedures. All my money is in there. I show my actual ID every time I transact at a bank branch, so I can understand if they are careful.
The things that annoy me the most when I travel are rarely banks – those tend to work just fine. It's usually the main trifecta – Facebook, Twitter, and sometimes Gmail.
> If you forget your password, they just email you a new one.
And in fact this is exactly what is so terrifying about Google moving more towards this kind of "oh you're in a different place, you must be a bad person" authentication. Email services are the single point of password recovery for almost all the websites you access. Sure, perhaps you'll lose a token; but most folks will learn to carry a couple over time. On the other hand, if Google locks you out because you look "too risky", you might lose access to multiple websites (because a lot of them these days email you security codes and such if you're logging in from a browser without cookies).
I know this is really sloppy of me but I'd argue my Gmail is as important if not more important than my bank account. If you have access to my bank, you have access to one bank account of mine but if you have control of my Google account, you now have access to all my bank accounts.
I agree though. I opted into two step authentication for a reason. If I give you both my password and two step code, add this entry to an append only table and move on.
I guess Facebook and Twitter will have this problem where people will take over someone's account and lock them out. Without going into too many details, I saw this happen to someone close to me. It is wild that there are scammers who do this for a living.
That makes me think of all the people who say they avoid staying in NYC homeless shelters because their shoes get stolen. How does a yubikey work for people who are in situations where they can’t reliably hang on to a single possession? Who provides customer service to people who only scrape together a few dollars a day? Hardware 2FA isn’t much of a solution for people who don’t even qualify to rent a P.O. Box.
Every single thing that I ever log into that does any kind of risk-based authentication triggers on me almost every single time (well over 90% of the time). Even things like Zoom installed locally on my laptop when I had to switch accounts for a couple of hours last week, when I went to switch back to my main account insisted on doing a code because I was allegedly logging in from a new location or device. (Aside: I have no idea why they present “switch accounts” and “sign out” as though they were different things. You’re fully signed out either way and have to sign in again.)
My only sins are having a dynamic IPv4 address, using Linux, using Firefox, and for some of them using Private Browsing windows for temporary sessions.
On Zoom at least, switching accounts and signing out/in seems to do something different. If I’m logged in with Google SSO, and I want to switch to a different Google SSO, clicking “Switch Account” and then selecting Google doesn’t let me change which account is selected. Actually signing out then back in does let me select a different Google account.
"Passwords are insecure" is not a good enough rebuttal to this, honestly. We have far more robust authentication methods available; and it's possible to make them standard and avoid this "Remember me" nonsense. Instead, we get all of it for what seems to be the sole purpose of even more user tracking.
----------------------------------------
[1] Remember those? A refresher if you don't: https://www.youtube.com/watch?v=iWssRVJgPqc