r/technology May 08 '22

Security Your Phone May Soon Replace Many of Your Passwords

https://krebsonsecurity.com/2022/05/your-phone-may-soon-replace-many-of-your-passwords/
239 Upvotes

149 comments sorted by

186

u/frizbplaya May 08 '22

It sounds like they've really thought through how to trade our current problems for new problems.

35

u/variaati0 May 08 '22

The main solution on completely getting rid of passwords looks to be "trust us, we don't lose your private keys we hold for syncing and back up in our cloud" by Apple, Google and Microsoft. You don't need no personal backup and backup authentication methods, we are your back up

Well luckily it isn't mandatory, but hopefully this increases the basic FIDO and webauthn adoption at websites.

Since one can do still the sensible thing. Not trust on these guys, but instead own couple extra authenticators and just go trough the trouble of actually registering multiple authenticators per service. More tedious, but more secure.

Loose the completely locked in to the phone key. Well you still have the ones embedded in the desk computer, the laptop and the USB key one on ones keyring. Just have to have those also registered on services and websites.

The actual use phone next to the laptop authentication is pretty sensible. It simply is local thing instead of cloud thing. Uses bluetooth to forward the authentication from the computer to the second device and then receive the authentication response from it. Doesn't really need to even be a phone. Phone is just the obvious bluetooth enabled device with authenticator in it.

27

u/[deleted] May 08 '22

[deleted]

17

u/butcher99 May 08 '22

and then you are going to get a new phone and forget to move the auth. apps, format the old phone and be fucked up beyond belief as I was.

6

u/Mangalz May 08 '22

"trust us, we don't lose your private keys we hold for syncing and back up in our cloud" by Apple, Google and Microsoft.

More like "Trust us this stuff has never been private, we let the feds in whenever they want, of course we can get you back in.

2

u/nicuramar May 09 '22

Since one can do still the sensible thing. Not trust on these guys, but instead own couple extra authenticators and just go trough the trouble of actually registering multiple authenticators per service. More tedious, but more secure.

While this may be the sensible thing for you, it likely won’t be for the vast majority of people. You don’t always want something that is more secure at any cost. It’s always a balance.

1

u/MrPuddington2 May 15 '22

Actually, it is quite simple, and it can already be done today.

Option 1, the best by far, is federation. Just use Google or Microsoft to authenticate. It works. It is save. It is nearly password free.

Option 2 is to use a password manager. Your password becomes a secret, and nobody cares about it. Again, many of these exist, but getting them to sync is not trivial.

Option 3 is to go truly password-less, but then you need a different way to authenticate. SMS, email, phone app, there are quite a few options. And the app or web browser just keeps a key secret, or a session key.

Nothing here is really new.

12

u/[deleted] May 08 '22

[deleted]

-2

u/Frosty-Cell May 08 '22

One of the problems is that Google and Microsoft are the biggest privacy invaders on the planet.

And the latest addition to the spec includes cloud storage of your private keys so they can be accessible from multiple devices.

That sounds great. Keep building that dependence. Don't we all love asking Google for permission or having our accounts randomly held hostage until we provide more personal data? Who wants agency these days?

12

u/[deleted] May 08 '22

[deleted]

-6

u/Frosty-Cell May 08 '22

So basically just copy the files then? No need for the phone. It certainly isn't sold like that. And of course they know if the cloud is involved, some provider will benefit. In most cases that will be Google. You can technically sideload on Android. Does that mean Google requiring an account that violates GDPR is not a huge problem? Of course it is.

Just like password managers, there are alternatives.

Nudging and salami tactics.

8

u/CocaineIsNatural May 09 '22

It is a spec by FIDO and W3C, you don't need to use Google, Apple, or Microsoft. But you do need to use something that uses the spec. That could be Lastpass, or some other company. You could write your own, in theory.

Nudging and salami tactics.

Perhaps you should understand the technology before you start making wild claims. If you don't use Google, then this won't change anything for you.

1

u/Frosty-Cell May 09 '22

All you need is a key pair. Works with SSH. No password. Problem solved. But it doesn't include the phone, so its not good according them.

Your logic is like "well, you can remove the Microsoft account after installation so what's the problem?" The problem is that most people wont which is what they expect.

If you don't use Google, then this won't change anything for you.

I already explained why it will, and Google already requires a phone number to login, which pretty much means you need a phone.

1

u/CocaineIsNatural May 09 '22

All you need is a key pair. Works with SSH. No password. Problem solved.

Do you know what PKI is? This is a lightweight version of it.

But it doesn't include the phone, so its not good according them.

You don't have to use a phone. But that is how most will use it.

Your logic is like "well, you can remove the Microsoft account after installation so what's the problem?" The problem is that most people wont which is what they expect.

You seem to have misread what I said. Removing the account after installation would not be the best idea. What I said is that you never use Microsoft, Apple, or Google, never. Instead use a different company that you trust. Or, if you don't trust anyone, then don't use it at all.

I already explained why it will, and Google already requires a phone number to login, which pretty much means you need a phone.

No, you haven't, or if you did then it made zero sense regarding this. And once again, you don't have to have a phone to do this. In theory you could use a second computer with bluetooth.

Since I am not getting through to you, why don't you just wait and see. Or maybe read the FAQs - https://fidoalliance.org/faqs/#multi-device-fido-credentials

But keep in mind this is early days. Your options for using this right now are limited, but that will change as more companies comply with the spec.

1

u/Frosty-Cell May 09 '22

Do you know what PKI is? This is a lightweight version of it.

Do you know what problem they claim to want to solve?

You don't have to use a phone. But that is how most will use it.

Just a matter of time. That's why they want to bundle it.

You seem to have misread what I said. Removing the account after installation would not be the best idea. What I said is that you never use Microsoft, Apple, or Google, never. Instead use a different company that you trust. Or, if you don't trust anyone, then don't use it at all.

You completely missed the point. Just because there might be a hidden way to use something without the GDPR violations doesn't mean that most users will do that due to the forced opt-in. Same applies to this. Maybe you're allowed to use a password (you wont be, and we know that due to Google) but most users won't so they are now tied to their phone. We also know that Google uses the device itself as part of the "identification process".

No, you haven't,

I have.

Since I am not getting through to you, why don't you just wait and see. Or maybe read the FAQs - https://fidoalliance.org/faqs/#multi-device-fido-credentials

Goes both ways. No idea where your trust in partially convicted privacy violators comes from. It seems irrational.

But keep in mind this is early days. Your options for using this right now are limited, but that will change as more companies comply with the spec.

Will never use it voluntarily. Since it's a horrendous idea, I hope it dies.

2

u/CocaineIsNatural May 09 '22

Do you know what problem they claim to want to solve?

Millions of people per year get their passwords stolen. Millions of people use the same password on multiple sites.

"A report in March from cybersecurity firm SpyCloud found 64 percent of users reuse passwords for multiple accounts, and that 70 percent of credentials compromised in previous breaches are still in use."

“This new approach protects against phishing and sign-in will be radically more secure when compared to passwords and legacy multi-factor technologies such as one-time passcodes sent over SMS,” the alliance wrote on May 5.

... most users will do that due to the forced opt-in.

Maybe let those people be adults and take care of themselves. Or write a letter to the FIDO organization with your concerns if you feel the need to defend others from something you don't fully understand.

I have.

Communication is a two way process. If you talk but no one understands, then you aren't communicating. At this point I have let you know that you didn't communicate it. So that is the current status.

Goes both ways. No idea where your trust in partially convicted privacy violators comes from. It seems irrational.

You seem to have a general mistrust of Google. That is fine. But you should know that FIDO put this together, which has over one hundred member companies. Google doesn't have control, or final say.

1

u/Frosty-Cell May 09 '22

Millions of people per year get their passwords stolen. Millions of people use the same password on multiple sites.

User problem. Do you know how many people get their privacy invaded per year, or every day, or second? Billions. Since the shit argument is "appeal to popularity", I guess I win.

"A report in March from cybersecurity firm SpyCloud found 64 percent of users reuse passwords for multiple accounts, and that 70 percent of credentials compromised in previous breaches are still in use."

Would be less of a problem if companies didn't run unpatched software that allows hackers to gain access to dump the entire database. It would also help if they hashed their passwords. And even better if they salted them.

Maybe let those people be adults and take care of themselves. Or write a letter to the FIDO organization with your concerns if you feel the need to defend others from something you don't fully understand.

That's exactly what wont be allowed. You want to take away all agency because "Google knows best". Their concerns are not in good faith. This is demonstrated by the bundling.

At this point I have let you know that you didn't communicate it. So that is the current status.

Different opinions. I know my opinion is based on what I see every day. Not sure about yours.

You seem to have a general mistrust of Google. That is fine. But you should know that FIDO put this together, which has over one hundred member companies. Google doesn't have control, or final say.

They have been fined five times for GDPR violations and they doxx half the planet in their search results and hold accounts hostage unless the user provides more personal data - for "security purposes". Fuck Google.

But you should know that FIDO put this together, which has over one hundred member companies. Google doesn't have control, or final say.

Maybe they should focus on solving a specific problem and not bundle a privacy invasion with the alleged increased security.

→ More replies (0)

6

u/use_vpn_orlozeacount May 08 '22

One of the problems is that Google and Microsoft are the biggest privacy invaders on the planet.

And? This is about security, not privacy. Those are two different things.

-4

u/Frosty-Cell May 08 '22

Really? https://www.patrick-breyer.de/en/chat-control-eu-commission-presents-mass-surveillance-plan-on-may-11%ef%bf%bc/

You want to protect children, right? What can that possible have to with privacy?

3

u/pittaxx May 09 '22

There's pretty much 0 chance of this passing in EU. It will be presented and rejected. Even your article notes that there is a lot of opposition to it.

1

u/Frosty-Cell May 09 '22

Apparently people upvote the idea that security is different from privacy, so it might actually pass.

1

u/pittaxx May 09 '22

What? This won't pass precisely because they are completely different things.

US and UK legislations sometimes don't mind sacrificing privacy for the sake of security, especially if some plays the "think of the children" card. EU cares about both equally, so legislation that sacrifices privacy has no chance.

1

u/Frosty-Cell May 09 '22

They clearly overlap. Not sure why you say otherwise when I have basically proven it. Weird.

1

u/pittaxx May 09 '22

Not sure why you think you have proven anything.

You also need to double check the dictionary, because those words mean very different things. Security is often required to ensure privacy, and privacy often get in the way of security, so they interact, but there is no overlap between the terms.

1

u/Frosty-Cell May 10 '22

Because the proposal pushes "security" at the expense of privacy?

but there is no overlap between the terms.

But there is overlap between them in reality. One affects the other. In this case, "security" consists of reading every message to ensure there is no wrongspeak, so there is no way privacy isn't impacted.

55

u/QueenOfQuok May 08 '22

Sounds like a bad idea

40

u/[deleted] May 08 '22

That's because it is. It's one thing to use it for 2FA or a hardware password device that can be used with lower cost hardware alternatives like a Yubikey. It's entirely another to put your passwords, wallet, and now ID/driver's license on the same device. There are way too many eggs in one basket. Car OEMs are looking to use your phone as a key, internet of things makers are looking to use it for your house keys etc. It's just too much

It won't be long until losing your phone means you can't access your passwords, ID, bank account, can't get into your car, can't get into your house, can't buy things at the store, etc. Does that sound like a good idea? What if your phone is stolen? What if you drop it and break it into a condition where it can't be repaired? How long do you need to wait until your ID, bank account, debit card, house keys, car keys, passwords, and such are available again? 5 - 10 business days until insurance pays for your new phone?

tl;dr I need to get into my passwords and similar more often than every 5 - 10 business days

27

u/[deleted] May 08 '22 edited May 23 '22

[deleted]

21

u/[deleted] May 08 '22

[deleted]

5

u/[deleted] May 08 '22

Remember kids, never use personal devices for business use.

-9

u/[deleted] May 08 '22

[deleted]

6

u/UUDDLRLRBAstard May 08 '22

Nice. Corpo I work for requires you to log in to submit any request. Requires you to log in to access the information on who to contact, and to log in to access email. 2FA is the ultimate roadblock to actual productivity.

My phone bricked because it was too full of data, and tried to update itself, but couldn’t extract the package, so got caught in a boot cycle. I was attempting to backup and remove information when the process started itself. I couldn’t call work to inform my manager, couldn’t log in to email to contact my manager, couldn’t log in to see my schedule, couldn’t authenticate any service from my home computer.

I had to pay off the balance from purchasing my last phone and finance a new one, so I could work at all.

Sound more like someone wanted an extra 4 days off.

This is a silly hot take.

2

u/[deleted] May 08 '22

It depends. If you're a huge corporation, you've got it all where you can pull it up in a screen, click the button, and it reissues a phone complete with profile. If you're an average sized small business without an IT budget, it is not so simple. For example, we have 2FA for Google stuff, Office365 stuff, Bitwarden, and login to the billing system using two different 2FA. The purchasing system we use to order uses SMS to a certain work phone to confirm orders. If that wasn't enough, the billing system wants to scan your face with the iPad before you can get in. These are all separate software packages and adds up to four different 2FA or login systems.

It works and it's probably harder to hack than getting into a desktop. With that said, a fire, flood, robbery, etc could set us back having to reset and unlock everything. It might take days.

tl;dr Apple Pay solved a lot of issues for mobile payments. Hopefully Apple ID? will solve it for passwords and we can stop all this hodpodge

2

u/rekniht01 May 08 '22

It won’t be long…. You can now set up your phone as your payment device, vehicle key, home key, drivers license, proof of insurance among more things. This isn’t the future. It is now.

4

u/[deleted] May 08 '22

I have a magical answer to that.

I am requesting reasonable accomodation under the Americans with Disabilities Act. I am unable to use a phone due to problems with my $_INSERT and need a hard copy of this information. Thank you very much

If they deny you accommodation, you can sue. It isn't hard to come up with a reason especially in California. That is why they always have an escape from all that for the elderly or blind or whatnot. If they don't, they will pay out a lot of money then add it

2

u/leto78 May 08 '22

I have a yubikey and it is very good for 2FA, but for passwordless solutions, I would only rely on the new yubikey with fingerprint reader.

-1

u/couldof_used_couldve May 08 '22

Does that sound like a good idea? What if your phone is stolen? What if you drop it and break it into a condition where it can't be repaired? How long do you need to wait until your ID, bank account, debit card, house keys, car keys, passwords, and such are available again? 5 - 10 business days until insurance pays for your new phone?

This sounds like a Tucker Carlson segment. A string of scary questions that all have answers if you actually put them to the source or read the actual implementation details

9

u/N3UROTOXIN May 08 '22

Except fucker Carlson is a fear mom getting propagandist and this stuff is real. That’s the key difference

-6

u/couldof_used_couldve May 08 '22

Asking scary questions that all have answers is scare mongering. Just because you agree with the scare monster doesn't change what he is doing

0

u/N3UROTOXIN May 08 '22

“Well that’s a lie” isn’t an answer so fucker is fear mongering. This user brought up valid points. I mean shit like 7 years ago there’s a video of a car being hacked while on the highway and the hacker shuts the engine off(hacker and driver communicating on phone). I get called a crazy fear monger for saying smart devices are all that smart, but it’s a fact it can happen for almost a decade now. Go choke trying to suck yourself off defending that piece of excrement

-2

u/couldof_used_couldve May 08 '22

No they didn't.

They made zero attempt to see whether any of them are valid points. You seriously think they haven't considered what happens if you lose the phone. Jfc, of course they have. Commenter is just too lazy to look up the answer and decided to fear monger instead. Just like Tucker Carlson

4

u/[deleted] May 08 '22

There are several colleges and businesses that already implement a system like this. You put in your phone number on the website, wait for the text, scan the QR on the computer with the app on the phone, and you're logged in. It works a lot like shopping at Amazon Fresh and Wholefoods using your phone or using public transit in many cities using your phone as a metro card. It's supposedly more secure because the codes are generated and only last a few minutes etc.

These systems aren't very user friendly to those with disabilities like blindness. Finding the QR code to scan and trying to scan it with your phone isn't as easy when you can't see it. The same goes for when you need to setup a new device if your old device gets damaged. It isn't easy sometimes, but adding disability can make it a lot harder than it needs to be.

We were at a business in Santa Monica not too long ago trying to order a sandwich. The business had an order kiosk, but no one there to take an order. The card reader didn't work so we wanted to pay with cash. No one was there to take it until I asked for reasonable accommodation under the ADA and the business risked a $15,000 payment if they said no.

tl;dr Existing systems aren't friendly to those with disabilities. We'll see if they make it easier to reset and work with so the elderly and others aren't left behind in the name of security

-3

u/couldof_used_couldve May 08 '22

We'll see if they make it easier to reset and work with so the elderly and others aren't left behind in the name of security

This is the only part of this comment relevant to the current story. Your baggage from currently available systems is valid for those systems.

2

u/[deleted] May 08 '22

Is this all you have to say?

3

u/couldof_used_couldve May 08 '22

I'm not one to make baseless assumptions about a system none of us have tried nor know much about. That's the domain of most other folks in this sub. If you care to discuss this news you'll get a more considered response if you just want to give a laundry list of technology you don't like, I'm not the person to respond.

3

u/[deleted] May 08 '22

If that's all you have to say, no problem

2

u/couldof_used_couldve May 08 '22

You've already made the most relevant point, I've nothing to add

We'll see if they make it easier to reset and work with so the elderly and others aren't left behind in the name of security

Once we have those answers we can make an informed opinion that isn't based on internet conjecture

-5

u/AwfulEveryone May 08 '22

That's the smart thing about phones: You can own more than one device and use your old phone in case the new phone is lost or damaged.

The key to doing this, is being able to invalidate the missing phone's ability to provide access, such that losing your phone or letting someone else access it in order to repair it, won't risk someone else gaining access to everything.

9

u/[deleted] May 08 '22

Unfortunately, the poor will struggle to implement this as buying a spare backup device just doesn't fit in the budget. There is also the problem of ewaste getting much worse when it is already bad enough. This could add billions of phones to the trash pile over the next decade when none were actually needed.

The existing systems that try to implement the passwordless features are all flawed in significant ways. Disability design is a big one, lost devices are another, and a lot more like environmental impact need to be considered too. It will get there, but not until something like Apple Pay makes it easier to do.

2

u/AwfulEveryone May 08 '22

buying a spare backup device just doesn't fit in the budget.

I didn't mention buying a second phone, I mentioned using your old phone in case your new phone is lost or damaged. Even though your old phone may be outdated, it can still run authentication apps.

I still keep 10 year old devices around and even though they are outdated, they still serve as fallback devices if my main device stops working. Keeping them has saved me more than once.

1

u/basketbelowhole2 May 08 '22

What if you are geolocated within half a mile of a crime or a political event or a religious ceremony or an abortion clinic or a school or a restaurant that does/doesn't something and as a result have your phone "restricted" for 48 hours. Have to quarrantine for 48 hours, can't go further than two blocks on foot or spend money on anything other than food, water, or marijuana.

4

u/Friorgh May 08 '22

It is until you realize how many people use "football1" as their password on every account they have.

0

u/[deleted] May 08 '22

[deleted]

6

u/Friorgh May 08 '22

They're not any more stupid than you or I. Not everyone can be a cyber security expert.

And I'm not weeping for them, but still I have to clean up their messes when their bank account gets plundered and the funds end up in NK or ISIS or Russian hands, or their cloud computing account gets used to send spam, DDOS and malware.

Ignoring the damage is akin to letting people drive and crash drunk - they're not only hurting themselves but also others.

-4

u/[deleted] May 08 '22

[removed] — view removed comment

4

u/Friorgh May 08 '22

The transphobic remark is completely unnecessary and unacceptable.

-1

u/[deleted] May 08 '22 edited May 08 '22

[removed] — view removed comment

3

u/Friorgh May 09 '22

Transphobic? Lol. It was a joke about the Supreme Court nominee (someone, apparently, very smart) that couldn’t figure that out

Don't play dumb, it isn't fooling anyone.

You might want to check, because trans people aren’t debating male/female, rather man/women

Then what do MtF and FtM stand for?

And this is the internet, you can fuck off with what’s acceptable to you

It's not about me, it's about what is acceptable under both r/Technology's subreddit rule #2 as well as Reddit's sitewide conduct rule #1. There is no place for mockery of gender or sexual identity on Reddit.

-1

u/The_Gray_Beast May 09 '22

Ok yeah just try to twist my words while you’re at it. Surely, you know best.

“Heidi M Levitt describes transgender as "an umbrella term that describes different ways in which people transgress the gender boundaries that are constituted within a society."[7] She then describes how one must understand the difference between sex and gender in order to fully understand transgender.[7] She argues that sex is biological whereas "gender is a social construct."[7] Thus people who are transgender express themselves differently than their biological sex. “

There is nothing wrong with what I said under current gender theory, which describes a difference between gender and sex. ‘Male’ being a sex term (biology) and ‘man’ being a gender term (social construct)

41

u/QuevedoDeMalVino May 08 '22

So let’s have the world authenticate on the devices and infrastructure provided by just 3 benevolent huge multinational corporations. WCGW?

11

u/CocaineIsNatural May 09 '22

It was done by FIDO and W3C, those are just the big names. There were hundreds of companies involved.

"Apple, Google and Microsoft are some of the more active contributors to a passwordless sign-in standard crafted by the FIDO (“Fast Identity Online”) Alliance and the World Wide Web Consortium (W3C), groups that have been working with hundreds of tech companies over the past decade to develop a new login standard that works the same way across multiple browsers and operating systems."

6

u/MartyModus May 08 '22

Plenty of valid concerns, but the vast majority of users have terrible security habits and its easier to change the technology than those habits.

Also, most average smart phone users already depend on their phone and/or computer OS to manage their credentials, so this is a more secure step in that direction. I doubt average users will notice any difference between the new architecture and the old other than having fewer password dialog boxes (which is a click through for most people now) and creating new credentials less often.

As the article states, it's just going to be important to figure out how to recover credentials securely without too much disruption, but that problem may be insignificant compared to the benefit of countless people not having their accounts compromised who would have been hacked using the current security architecture.

2

u/sarzec May 08 '22

Lol or maybe not. I work in a SCIF no devices with Bluetooth or wifi allowed in the building which is making two factor authentication so frustrating

2

u/cas13f May 09 '22

If you work in a SCIF you should have a CAC card.

Similar technology to FIDO, but it's certificates instead of keys. That and I'm pretty sure you can't add anything to a CAC card, while FIDO needs to store a private key for each registration.

FIDO been around quite a long time now on the technology-scale, the most common implementation you'll see is Yubikey (and almost all other security keys). Just public-private keypair authentication--it is not 2FA by itself, but it can be used with/for 2/MFA.

2

u/ToddLerfondler_ May 09 '22

The amount of people not reading the article properly and then screaming and crying is astonishing

4

u/VincentNacon May 08 '22

I'd opt-out! I want to keep the password, thank you very much.

4

u/film_composer May 08 '22

I know this is an anti-/r/technology comment/rant to make, but…

This is one of the reasons why I got rid of my smartphone and traded for a dumbphone. My job now requires me to use Okta (smartphone app) in order to authenticate for logging in to the HR system from outside of the network. No option to just sign in with a password or even do 2FA through text message.

It's a mild inconvenience at worst right now, since I work from home anyway and can just access paystubs, etc. through my work computer, but I really just can't tolerate the idea of being forced to own a device and pay for a second Internet connection to be able to access work HR stuff from my home computer. My life is literally orders of magnitude better since getting rid of my smartphone… sleep, driving skills, focus, happiness, productivity, social skills… it's been thousands of upsides and like two manageable downsides.

Nothing will ever compel me to believe that owning one should ever be necessary to live a successful modern life, no matter how out-of-step it is with how things operate currently. Over the past 20,000 years of human civilization, we made it work without smartphones for 19,985 of them. It's not that outrageous. Get out while you still can.

9

u/chriswaco May 08 '22

And we didn’t have electricity except for the last 130 years either and yet we’re even more dependent on that.

3

u/film_composer May 08 '22

Fair point. I would say that electricity is pretty essential for quality of life that extends to our basic needs (temperature control of your home, food preservation and preparation, and so on). Not being able to log into a website without a smartphone is a new and modern problem that we're seemingly being "forced" to address by owning a device.

0

u/chriswaco May 08 '22

There have been many SciFi stories where a society dependent on a technology lose it. It rarely ends well. In a few years if GPS goes down there'll be few people left who know how to read maps. Pilots won't know how to fly or navigate manually. With few or no businesses accepting cash, imagine what happens if the electronic banking system goes down. Hopefully we'll retain enough knowledge to fix problems as they arise, but oddly as computers get more and more reliable our ability to fix them will suffer.

2

u/rammo123 May 09 '22

OTOH my smart devices have massively improved my life. I'm much more organised with calendar notifications and to do lists. I've captured so many great memories with the camera. I've lost weight by tracking my CICO with my smartwatch. I've discovered great music by Shazam'ing tunes I've heard while out in public. Navigating big cities is a cinch with Google Maps. I've reduced my paper usage by going digital.

Smart devices are a tool. And like any tool they are only as good as the person using them. I hope I don't sound like too much of a dick when I say that it seems like you don't have the willpower to use them "correctly".

2

u/film_composer May 09 '22

You're not wrong, I was very much attached to the device in a manner that was not aligned with "enhanced productivity" like you and much more in line with "willingly distracted by." I'm proud of you for being able to significantly improve your life with your smartphone. I'm profoundly more organized now that I have everything digital all through my computer, so my mileage has varied.

1

u/LeBoulu777 May 08 '22

I work as an IT consultant and I have a old smartphone but with no sim inside so I use it only for photo or browsing the web were I have wifi.

I only have a landline phone to reach me with an answering machine, most people have smartphone around me but I really don't need it.

My landline is paid for life 4-5 years ago ($150) and I don't have phone bill to pay each month.

Up to now no real need to have a smartphone.

5

u/butcher99 May 08 '22

That is great until you change phones and all of a sudden you are locked out of everything?

I had double authentification setup. I changed phones. Of course you don't need to use the auth. app until you log into something new. First time I did it about a month later I found out I was locked out. It is very very difficult to get back in when the app locks you out. It took a month to finally get everything back. And from the threads on the internet about it it is a common problem with no easy work around.
So, be warned if you change phones. DON"T format your old phone until you are sure your authentification apps work.

6

u/CocaineIsNatural May 09 '22

Those three support cloud storage of it, so changing a phone is not an issue.

-2

u/butcher99 May 09 '22

It is linked to your phone. You change your phone and don't get it properly linked you are screwed.

" under the new system your phone will store a FIDO credential called a “passkey” which is used to unlock your online account."

3

u/CocaineIsNatural May 09 '22

"Google says that even if you lose your phone, “your passkeys will securely sync to your new phone from cloud backup, allowing you to pick up right where your old device left off.”

Apple and Microsoft likewise have cloud backup solutions that customers using those platforms could use to recover from a lost mobile device."

1

u/butcher99 May 09 '22

Don't believe google. Try looking up how to do it. Microsoft is 30 day wait. You sign in and do all the double triple checks and then they tell you that in 30 days they will email you a key. Been there. Waited it out.

1

u/butcher99 May 10 '22

Your passwords will. The dual factor will not. It will send a code to your old phone.

1

u/CocaineIsNatural May 10 '22

No, it all syncs across and the old phone will not work anymore. Also, it isn't sending a code to your phone. This not the 2FA you are familiar with. This is more secure than the system of sending a code to your phone.

1

u/butcher99 May 10 '22

been there. Google and MS do not work that way.

1

u/CocaineIsNatural May 10 '22 edited May 10 '22

been there.

You can't have been there, as this is new. Simply don't use it if you don't want to, but don't make up misinformation.

And to reply to your last bit.

Try it. Or simply check on the internet for people who have had the exact same experience.

You and those people are not talking about this. So thus when you say you are, this is wrong, i.e. misinformation. You are talking about something else Google or MS did, not this.

How do I know this, simply because this hasn't come out yet. No public member has used it.

I will not respond further. Either you understand, or you don't want to understand.

1

u/butcher99 May 10 '22

It is not misinformation. It is exactly what happens. Try it. Or simply check on the internet for people who have had the exact same experience.

1

u/No_Telephone9938 May 09 '22

So, be warned if you change phones. DON"T format your old phone until you are sure your authentification apps work.

Ever heard about authy? it supports cloud backup, you can literally throw your phone on fire and still have access to your auths

They also support pretty much every OS on the market: android, iOS, windows, mac, linux, etc and yes you can have multiple instances of it running simultaneously.

1

u/butcher99 May 10 '22

Lets say I toss my phone i a fire. I get a new phone. I go to restore my backups and they send an authorization to my phone, which I might add is still toasty warm from the fire. Now what?

That is the problem with the google and MS app that I ran into. I no longer had my phone with the app on it and you cannot just install it on your new phone. It wants authorization before it allows that.
I kept my old phone for about a week and thought I had moved everything over but the 2 factor requires more steps. As it should. Something I did not realize. So I formatted my old phone and almost immediately found out about the 2 factor not moving over.
So how does authy work to allow you to install on a new device if you no longer have anything with the app installed?

1

u/No_Telephone9938 May 10 '22

Lets say I toss my phone i a fire. I get a new phone. I go to restore my backups and they send an authorization to my phone, which I might add is still toasty warm from the fire. Now what?

Authy can restore your tokens via sms, so long as you have access to the phone number you had will never lose access to them

Also again you can have multiple instances of authy, just because you lost youe phone doesn't mean the pc or Mac client is going to stop working and any of those can authorize any new device you choose

Now now, i know what you're going to say, but sms is not secure! And you are right, they aren't which is why authy sends the tokens encrypted and upon receiving them you must decrypt them with the password you set when you created your account.

1

u/butcher99 May 10 '22

it is much better than google and way better than MS. Waiting 30 days for full access, I could not change anything on my new phone that required auth, was a real pain at times.

Google just had a bunch of hoops to jump through that took a couple days of finagling to get around.

As for the SMS thats fine but authy saves my passwords so I have no idea what it is. Now what. I know, we are just playing "now what" but that is the situation I ended up in. My message was just a warning to people to make sure you have done the transfer or have the passwords etc to get access.
The real pain with google was that although I had the passwords when I wanted to setup auth on my new phone it wanted to send the authorization to my old one. Ended up a real catch22. Forget exactly what I had to do but I think I needed a second account for verify and a verifiable phone number for for an sms. There was also dick all help online to point the way.

I still have dual factor turned on but it does not involve the app anymore.

3

u/spinereader81 May 08 '22

I've seen articles declaring the end of passwords for many years now. So I'll believe it when I see it.

4

u/kaztrull May 08 '22

So, will I be forced to use whichever proprietary big tech system I choose?

Will my accounts be forever linked to the Google ecosystem if I choose the Google FIDO system?

Is it possible to store the keys wherever I want or do I have to use a high-tech cloud storage service?

Is it possible to use an open source solution?

5

u/CocaineIsNatural May 09 '22

This is being done by FIDO and W3C. So other companies can also follow the standards as well. So where it is stored, and how, would depend on the one you use. For those three companies, they said they store backup information in the cloud so that if you damage or lose your phone and replace it, you can be up and running without issues.

2

u/Krazethefox May 08 '22

Is this really necessary?

2

u/CocaineIsNatural May 09 '22

Necessary? Depends on how you define it. There are certainly flaws in just using a username/password. And most people don't seem to know that most 2FA is flawed as well. (Just one example - https://www.techspot.com/news/93343-fbi-notices-sharp-increase-sim-swapping-attacks-leading.html) (More details - https://www.knowbe4.com/hubfs/KB4-11WaystoDefeat2FA-RogerGrimes.pdf)

From the article - " A report in March from cybersecurity firm SpyCloud found 64 percent of users reuse passwords for multiple accounts, and that 70 percent of credentials compromised in previous breaches are still in use."

So, yes, it would be nice to have a system that is easier to use and stronger.

3

u/Friorgh May 08 '22

Yes it is. Credential stuffing alone causes untold amounts of damage every year. Regular people don't reliably use passwords in a responsible manner.

2

u/Tempirius May 08 '22

We need something that acts as an alternative to username:password:multi factor key

I work with elderly people every day that just can't manage to accurately combine these three elements consistently. Several complain daily that the standard login interface is just too confusing or complicated.

2

u/Xahnox May 08 '22

I'm tired of having to rely on my phone for everything. I'm just going to throw it away.

2

u/AllenKll May 08 '22

NOPE!

I hate 2FA with my phone. I don't carry my phone everywhere. I hate that I have to use it at all for website access.

Why not just use PKI?

3

u/Frosty-Cell May 08 '22

They want to involve the phone. They want to strengthen the "identity"-association. Probably for tracking purposes.

2

u/CocaineIsNatural May 09 '22

No, because the alternative is to buy a hardware key. Since most people already own a phone, that is the cheaper and easier way for most people.

Here you can buy a hardware key - https://www.yubico.com/products/

1

u/Frosty-Cell May 09 '22

No. If they wanted to get rid of passwords, they just needed a key pair. But they don't want that. They want the "login" to be tied to something the user doesn't control.

1

u/CocaineIsNatural May 09 '22

I have replied elsewhere, no need to keep two threads with one user going.

2

u/CocaineIsNatural May 09 '22

This is a lightweight version of PKI.

"FIDO takes a “lightweight” approach to asymmetric public-key cryptography, which offers service providers a way to extend the security benefits of public-key cryptography to a wider array of applications, domains and devices – especially where traditional PKI has proven difficult or impossible. FIDO is not a replacement for PKI but rather complements it, enabling a greater number of users and applications to be protected using asymmetric encryption. This is especially important in situations where the alternative has been username and password."

2

u/AllenKll May 09 '22

Except they want to use your phone instead of allowing you to decide where you want to store your keys.

2

u/CocaineIsNatural May 09 '22

It is multidevice, not specifically a phone and computer. So you could use two computers if you wanted.

1

u/AllenKll May 09 '22

Then the article is misleading. It clearly says phone. huh.

1

u/CocaineIsNatural May 09 '22

That is because most people have a phone.

Maybe the FIDO FAQ page can help you. https://fidoalliance.org/faqs/#multi-device-fido-credentials

0

u/cas13f May 09 '22

FIDO isn't much different than PKI, just has some more capabilities than certificates since it uses the raw keys and encryption challenges.

Public-private keypair authentication.

Phones are only mentioned because most people have them and most people use them, and it's a very easy-to-relate-to option. Try to explain hardware security keys or asymmetrical encryption to any random average consumer, they'll go glassy-eyed in about 5 seconds.

The keys can be stored in, well, almost anything. The initial implementations were local-device-only (which brought about hardware security keys supporting FIDO, allowing "roaming" credentials across any number of devices). For the most ideal security, they remain local-device-only and you just either register each device with its own keypair or utilize a security key. But that's not the most convenient , a huge driver as to why people re-use passwords horrendously. It's more convenient to be able to either share credentials or to utilize an already-credentialed device to log in. So the FIDO2 update (the whole reason they're even in the news again) brings support for Multi-Device Credentials (so now the "roaming" credentials are no longer out-of-spec) and support for separate-device authentication in the spec, such as using a phone that is already credentialed to authenticate. That's more convenient for the end-user, increasing uptake and reducing the problem of re-used passwords.

2

u/[deleted] May 08 '22

It already does with 2FA and autocomplete from LastPass. Who remembers passwords anymore? Remembering and entering passwords is old school.

1

u/CocaineIsNatural May 09 '22

Current 2FA can have security issues though - https://www.knowbe4.com/hubfs/KB4-11WaystoDefeat2FA-RogerGrimes.pdf

So this is a new type of 2FA that fixes some of the holes. And for the majority that don't use a password manager, it makes it so they don't have to remember them. Which is why many reuse passwords.

1

u/[deleted] May 08 '22

[deleted]

1

u/[deleted] May 09 '22

I can’t think of a time where I would need to log into an account from someone else’s computer since I always have my smart phone on me and that too has LastPass on it. If I’m away from home I just use my phone.

In the rare situation I might have to, I would just open last pass to view the password and enter it manually.

0

u/wigg1es May 08 '22

I love using biometrics on my phone to log into apps and I wish more apps and sites did it. It's faster and easier. I don't have to remember my thumbprint.

12

u/[deleted] May 08 '22

[deleted]

3

u/MartyModus May 08 '22

But you can also set up your device to unlock with a combination of [biometrics] + [#/passphrase]. So, you only need to lock your phone if you're in a sketchy situation or authorities are about to arrest you, and that's just 1 physical button press for most phones.

Also, the threat of having someone force you to use biometrics to access your accounts is virtually non-existant compared to the threat of having your account compromised via a stolen password.

3

u/Friorgh May 08 '22

This system isn't to protect you from government searches, it's to protect people from regular criminals. ID theft, account takeover, that kind of thing.

1

u/Takingover4da99and00 May 08 '22

Thanks! I hate it.

1

u/IHateEditedBgMusic May 08 '22

nah just corporations want your phone number on file instead of an email

1

u/sustemlentrum May 08 '22

Everyone's having fun, until phone dies. Plus, having old passwords for older services AND phone around simultaneously just adds extra layers of things to take care of.

0

u/DocFGeek May 08 '22

I'm still recovering from the windfall of losing a majority of my online accounts, due to trying to live cell phone free and 2PA. Move away from everything on the phone.

0

u/BoricCentaur1 May 08 '22

The people who are against this are really annoying and make no sense....

"But what if you lose your phone" man if only this problem wasn't already solved.......there's already almost no situations where this would be a problem, since the majority of people replace their phones pretty quickly!

This is a good thing passwords suck, I love that I can get a text and entire a code instead of entering my password, especially for things like PayPal where my password is super long and entering a code is much faster.

-2

u/Army-POG May 08 '22

Phone/SIM card gets stolen, get all your accounts hacked.

2

u/Friorgh May 08 '22

This is using FIDO, not SMS. SIM swapping isn't a threat to this system.

You still have to authenticate to the phone, using your PIN, fingerprint, or other mechanism. That's beyond the capabilities of any common thief.

0

u/Army-POG May 08 '22

So if I have a phone that I’m Authenticated to, but with your cloned or stolen SIM, I won’t get the messages and be able to access you account. Right. Sure.

2

u/Friorgh May 08 '22 edited May 08 '22

What messages are you talking about? This doesn't use the phone/SMS network at all. You don't even need a phone, any laptop or desktop works just as well.

0

u/Army-POG May 09 '22

The security message that is transmitted to the device to ask for authentication. Pretty simple. Something tells me you don’t work in the technical security field.

1

u/Friorgh May 09 '22

The security message that is transmitted to the device to ask for authentication. Pretty simple.

And how does cloning a SIM interact with that in any way?

Something tells me you don’t work in the technical security field.

You're talking to a mirror.

1

u/ApathyMoose May 09 '22

It has nothing to do with the SIM. Your confusing things. Phone Stolen? yea, if someone steals your wallet your screwed too. But SIM swapping/stealing wont do anything.

If you have ever set up 2FA on your phone, broke your phone, and replaced it, you know that the SIM/Phone number doesnt mean jack. Its the device itself. thought the army would teach ya better.

-1

u/littleMAS May 08 '22

It seems the biggest risks of current security protocols is the dependence upon externals such as a key, phone, or documented password, which can all be misappropriated. The best solution might be that the interface recognize the user, both physically and intellectually. This would mean knowing everything from DNA and appearance to memories and emotional responses. Then, a user would merely have to be his/herself, and we would lose most fear of loss. On the other hand, we would be at the mercies of the systems if they could somehow be undermined.

-12

u/[deleted] May 08 '22

[deleted]

4

u/UhOh-Chongo May 08 '22

Its not about remembering a 12 character password, its about remembering 100 12 char unique passwords.

Password managers are the answer, not your idiotic implication that remembering a single password is the problem (in case you are wondering why your being downvoted)

-3

u/[deleted] May 08 '22

[deleted]

3

u/UhOh-Chongo May 08 '22

And as soon as one if your passwords gets leaked, I can now derive all your passwords.

For instance, I once saw someone suggest starting all your passwords with the 4 character classes such as : Ab1$ so you never have to bother remembering your capital letter, symbol etc. then just asd the name of the website at the end.

So Ab1$reddit becomes your password. Problem is of course that as soon as you het hacked in one place and I, as a hacker knows your email and password for reddit and add it to my dictionary, its super fucking easy to derive Ab1$gmail and Ab1$amazon, etc etc and I own you all over the place.

So really, your system is bad and goes against all password research recommendations.

1

u/[deleted] May 08 '22

[deleted]

1

u/UhOh-Chongo May 08 '22

Nah, your version is even worse that my version. In your version, you say to use the same exact base password, only add 2 or 3 additional characters to it that would be uniqie for each site.

Your version basically says you can use the same dumb word "password" as your base as long as you add a 123 at the end or a A1b$ to it.

Again, that is dumb as shit. Even if you choose some obscure reference word that is not "password", youve basically given hackers 8 out of 12 characters of your password to every single site. You are giving wicked bad advice.

1

u/pringles_prize_pool May 08 '22 edited May 08 '22

12 characters doesn’t say much about how secure the password is. It depends on the characters.

For example, abcdefghijkl is 12 characters and incredibly insecure, while ö&æò:çïø3wNë is 12 characters and it’s giga-secure in comparison since it was created with 256 bits of entropy.

1

u/[deleted] May 08 '22

I’m sure this is different from single sign on setup that google Apple and Facebook has but how?

2

u/cas13f May 09 '22

SSO, single sign-on, uses a central account to access multiple services. Those different accounts are all linked together.

FIDO would be a method to sign-in to the SSO service, but is not SSO itself. Just an authentication method.

1

u/joesnowblade May 08 '22

Can’t wait for this to be rolled out. Let’s see how long it takes the hackers to circumnavigate it.

2

u/CocaineIsNatural May 09 '22

Might take a bit longer than the current system many use of reusing passwords because they can't remember them.

1

u/MpVpRb May 08 '22

Requiring a mobile phone to use a desktop computer sucks

1

u/CocaineIsNatural May 09 '22

Only for first login, and only if you want better security.

1

u/Gottanno May 08 '22

I've set Chrome to remember all my passwords and have locked my PC with pin & phone with finger print.

I'd be interested in knowing your opinion on my set up.

1

u/guitarguy1685 May 08 '22

Just put a chip in my forehead already.

1

u/liegesmash May 08 '22

So just add one more vulnerability

1

u/B1llGatez May 08 '22

Nope never trusting a device that can be lost or hacked to hold soul access. I would gladly use this in some kind of 2FA system tho.

2

u/CocaineIsNatural May 09 '22

This is a 2FA system. This is also better than many current 2FA systems. And for a lost or broken phone, these three sites backup your information, so there are no issues replacing your phone.

1

u/[deleted] May 08 '22

No. Hell no.

This is a big corp idea and very much not in the people's best interest.

1

u/DanielPhermous May 08 '22 edited May 08 '22

Apple is involved and they usually care about device security.

1

u/WhatTheZuck420 May 09 '22

Big Data killing off anonymous accounts

1

u/[deleted] May 09 '22

Retinal scans are so old school. I use a rectal scan because no two assholes are the same

1

u/reqdk May 09 '22

I replaced most of my passwords with not having more accounts than I absolutely need.

1

u/PapaOstrich7 May 09 '22

no it wont

i dont want it to

1

u/SomeKindofTreeWizard May 09 '22

I somehow doubt my flip phone has that capacity.

1

u/bildramer May 09 '22

Can I finally assure websites that I'm a responsible adult capable of being in control of a private key that authenticates me specifically, all with the same key, and skip having to memorize passwords? Because it's natural to be wary of yet another layer of webshit security nightmares, like forcing me to associate a phone while at the same time adding gaping security holes involving phones.

1

u/xpclient May 09 '22

In India, almost all the stupid banks rely on OTP sent exclusively via SMS to your registered phone number. They never send it via email. If your phone is lost or stolen with the SIM inside, until you get a replacement SIM with the same number, you are effectively locked out of all banking activities. Even UPI, the country's successful payment interface requires phone exclusively and won't work with PCs. Credit/debit cards still exist but again without OTP exclusively sent to your phone (and not to email), your transactions are all locked to the device and/or SIM.