Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • Remote
  • Global
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • Remote
  • Global
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Sketchy)
  • No Skin
Collapse
Wandering Adventure Party Logo
  1. Home
  2. General Discussion
  3. I’m gonna need everyone in security to internalize this.

I’m gonna need everyone in security to internalize this.

Scheduled Pinned Locked Moved General Discussion
1 Cross-posts 38 Posts 22 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • TindraT This user is from outside of this forum
    TindraT This user is from outside of this forum
    Tindra
    wrote on last edited by
    #1

    I’m gonna need everyone in security to internalize this.

    Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

    Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

    If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

    F Epic NullE Haelwenn /элвэн/ :triskell:L Todd KnarrT BrahvimB 11 Replies Last reply
    2
    1
    • R AodeRelay shared this topic on
    • TindraT Tindra

      I’m gonna need everyone in security to internalize this.

      Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

      Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

      If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

      F This user is from outside of this forum
      F This user is from outside of this forum
      OddOpinions5
      wrote on last edited by
      #2

      @TindrasGrove

      I think about 95% of adults in wealthy countries have a smart phone

      So about 95% have access to online registration ?

      of th remaining 5% a lot are grouches like me, I don't have a smartphone but can obviously can use the internet

      of the remaining what, 1% of adults who don't have a smartphone or a laptop, maybe 50% can access these things at a library ?

      roughly ?

      very few systems work smoothly for the last half percet

      cubeQ 1 Reply Last reply
      0
      • TindraT Tindra

        I’m gonna need everyone in security to internalize this.

        Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

        Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

        If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

        Epic NullE This user is from outside of this forum
        Epic NullE This user is from outside of this forum
        Epic Null
        wrote on last edited by
        #3

        @TindrasGrove It seems to me the appropriate form of two factor for an in person event would be... an in person item. Like a physical piece of paper.

        1 Reply Last reply
        0
        • Pteryx the Puzzle SecretaryP Pteryx the Puzzle Secretary shared this topic on
        • TindraT Tindra

          I’m gonna need everyone in security to internalize this.

          Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

          Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

          If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

          Haelwenn /элвэн/ :triskell:L This user is from outside of this forum
          Haelwenn /элвэн/ :triskell:L This user is from outside of this forum
          Haelwenn /элвэн/ :triskell:
          wrote on last edited by
          #4
          @TindrasGrove Kind of thing which also often makes me wonder what happens if someone looses their phone and they got all their sms/2fa stuff in it.

          Wouldn't even be surprised that it would be a struggle to buy a new sim card, and well last time I bought a cellphone they wanted the number for the delivery (usually to ping beforehand or in case bell/intercom doesn't works).
          TindraT 1 Reply Last reply
          0
          • GnPG This user is from outside of this forum
            GnPG This user is from outside of this forum
            GnP
            wrote on last edited by
            #5

            @mirabilos @TindrasGrove I agree with the general point of usability (and accesibility!) over security.

            But 2fa does improve security, a lot. Some studies show that it reduces hacks by over 90%

            1 Reply Last reply
            0
            • Scott VE3QBZS This user is from outside of this forum
              Scott VE3QBZS This user is from outside of this forum
              Scott VE3QBZ
              wrote on last edited by
              #6

              @mirabilos @TindrasGrove even devices forcing a PIN or passcode is bullshit. I'm looking at you, iPad, that never leaves the grandparents house.

              1 Reply Last reply
              0
              • Haelwenn /элвэн/ :triskell:L Haelwenn /элвэн/ :triskell:
                @TindrasGrove Kind of thing which also often makes me wonder what happens if someone looses their phone and they got all their sms/2fa stuff in it.

                Wouldn't even be surprised that it would be a struggle to buy a new sim card, and well last time I bought a cellphone they wanted the number for the delivery (usually to ping beforehand or in case bell/intercom doesn't works).
                TindraT This user is from outside of this forum
                TindraT This user is from outside of this forum
                Tindra
                wrote on last edited by
                #7

                @lanodan I would rather lose my wallet than my phone.

                darf :BlobhajMlem:D 1 Reply Last reply
                0
                • Scott VE3QBZS This user is from outside of this forum
                  Scott VE3QBZS This user is from outside of this forum
                  Scott VE3QBZ
                  wrote on last edited by
                  #8

                  @mirabilos @TindrasGrove grandma doesn't need encryption at rest either lol

                  1 Reply Last reply
                  0
                  • Buttered JortsA This user is from outside of this forum
                    Buttered JortsA This user is from outside of this forum
                    Buttered Jorts
                    wrote on last edited by
                    #9

                    @mirabilos except if you log in on a device with a stealer or force your password manager to fill on a phishing site, 2FA prevents persistent access to your account. And yeah, for everything except the critical stuff I store my TOTP in the same password manager as the user/password credentials, but for those few critical systems (including my email and password manager), I have separate factors.

                    Too many systems make it mandatory when they shouldn’t, or only support factors that make it nearly moot (looking at you, email/SMS OTP). But saying it adds nothing but inconvenience ignores a whole lot of threats that it complicates or outright prevents

                    ✨buff dog himbo✨I 1 Reply Last reply
                    0
                    • Buttered JortsA Buttered Jorts

                      @mirabilos except if you log in on a device with a stealer or force your password manager to fill on a phishing site, 2FA prevents persistent access to your account. And yeah, for everything except the critical stuff I store my TOTP in the same password manager as the user/password credentials, but for those few critical systems (including my email and password manager), I have separate factors.

                      Too many systems make it mandatory when they shouldn’t, or only support factors that make it nearly moot (looking at you, email/SMS OTP). But saying it adds nothing but inconvenience ignores a whole lot of threats that it complicates or outright prevents

                      ✨buff dog himbo✨I This user is from outside of this forum
                      ✨buff dog himbo✨I This user is from outside of this forum
                      ✨buff dog himbo✨
                      wrote on last edited by
                      #10

                      @ajn142 @mirabilos really don't think anyone has actually said that 2fa never has any practical use case beyond making things inconvenient. What was said is that for many people it completely removes them from an increasing number of aspects of normal public life that they should be entitled to participate in as a bare human being without being required to have a mobile device or computer to have access.

                      Buttered JortsA 1 Reply Last reply
                      1
                      • ✨buff dog himbo✨I ✨buff dog himbo✨

                        @ajn142 @mirabilos really don't think anyone has actually said that 2fa never has any practical use case beyond making things inconvenient. What was said is that for many people it completely removes them from an increasing number of aspects of normal public life that they should be entitled to participate in as a bare human being without being required to have a mobile device or computer to have access.

                        Buttered JortsA This user is from outside of this forum
                        Buttered JortsA This user is from outside of this forum
                        Buttered Jorts
                        wrote on last edited by
                        #11

                        @itsmeholland @mirabilos

                        That’s more like 10 than 15 seconds, and in no way an increase in security.

                        From the post I was replying to :)

                        1 Reply Last reply
                        0
                        • TindraT Tindra

                          @lanodan I would rather lose my wallet than my phone.

                          darf :BlobhajMlem:D This user is from outside of this forum
                          darf :BlobhajMlem:D This user is from outside of this forum
                          darf :BlobhajMlem:
                          wrote on last edited by
                          #12

                          @TindrasGrove @lanodan as someone who has their phone smashed to an inoperable state, it left me very isolated for the 4 days I was in the ICU until I could get back to my home wifi to MFA back into my account, even with a highly trusted person clicking the 2FA auth for my Google account, it still denied my log in because the auth and 2fa were too far apart 🙃

                          1 Reply Last reply
                          0
                          • TindraT Tindra

                            I’m gonna need everyone in security to internalize this.

                            Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                            Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                            If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                            Todd KnarrT This user is from outside of this forum
                            Todd KnarrT This user is from outside of this forum
                            Todd Knarr
                            wrote on last edited by
                            #13

                            @TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...

                            Todd KnarrT Daniel LeighD Epic NullE 3 Replies Last reply
                            0
                            • TindraT Tindra

                              I’m gonna need everyone in security to internalize this.

                              Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                              Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                              If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                              BrahvimB This user is from outside of this forum
                              BrahvimB This user is from outside of this forum
                              Brahvim
                              wrote on last edited by
                              #14

                              @TindrasGrove Precisely. Locking people out by not providing accessibility is a bad idea as-is, but forcing the usual "Banking-App DRM" etc. is a worse idea. It's not about "Haha, you don't own a phone!", reader! Batteries and internet limits exist!

                              1 Reply Last reply
                              0
                              • Todd KnarrT Todd Knarr

                                @TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...

                                Todd KnarrT This user is from outside of this forum
                                Todd KnarrT This user is from outside of this forum
                                Todd Knarr
                                wrote on last edited by
                                #15

                                @TindrasGrove ... a hardware key (eg. Yubikey), or a printed list of auth codes.

                                No, we don't like it any more than you do. Thank the swill-licking bargepole-swallowers who try to attack anything and everything just for kicks, and the even scummier crooks who pay them for credentials.

                                1 Reply Last reply
                                0
                                • TindraT Tindra

                                  I’m gonna need everyone in security to internalize this.

                                  Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                                  Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                                  If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                                  Ooze 𓁟O This user is from outside of this forum
                                  Ooze 𓁟O This user is from outside of this forum
                                  Ooze 𓁟
                                  wrote on last edited by
                                  #16

                                  @TindrasGrove Not to mention the non literate being excluded.

                                  1 Reply Last reply
                                  0
                                  • Buttered JortsA This user is from outside of this forum
                                    Buttered JortsA This user is from outside of this forum
                                    Buttered Jorts
                                    wrote on last edited by
                                    #17

                                    @mirabilos correct, but best practice is that when changing security information such as password, email, or adding another 2FA factor you’d need to authenticate again, including 2FA. So while it won’t stop the account from being accessed or abused, it does help prevent takeover. I was specific about persistent access there for a reason.

                                    Also protects against credential stuffing in the case of reused passwords, which is likely a bigger risk to the average person.

                                    1 Reply Last reply
                                    0
                                    • TindraT Tindra

                                      I’m gonna need everyone in security to internalize this.

                                      Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                                      Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                                      If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                                      Carmen-LisandretteC This user is from outside of this forum
                                      Carmen-LisandretteC This user is from outside of this forum
                                      Carmen-Lisandrette
                                      wrote on last edited by
                                      #18

                                      @TindrasGrove Most things should be able to be done offline.

                                      The burden obviously falls disproportionately on the poor, immigrants, illiterate, elderly or disabled. But also a surprising amount of people simply feel alienated by online services.

                                      I think it would be helpful if more people who are more privileged chose to do things offline where possible. It makes it easier for companies and the government to justify the expense for people who are marginalised.

                                      1 Reply Last reply
                                      0
                                      • Todd KnarrT Todd Knarr

                                        @TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...

                                        Daniel LeighD This user is from outside of this forum
                                        Daniel LeighD This user is from outside of this forum
                                        Daniel Leigh
                                        wrote on last edited by
                                        #19

                                        @tknarr @TindrasGrove SMS, email, and other "less secure" 2fa methods are far from useless. They prevent untargeted attacks. If your threat profile includes a persistent attacker going after you specifically, sure they are insufficient, but that isn't a reasonable threat profile for a vast majority of accounts on any service.

                                        Todd KnarrT 1 Reply Last reply
                                        0
                                        • TindraT Tindra

                                          I’m gonna need everyone in security to internalize this.

                                          Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.

                                          Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?

                                          If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.

                                          Franceska MannF This user is from outside of this forum
                                          Franceska MannF This user is from outside of this forum
                                          Franceska Mann
                                          wrote on last edited by
                                          #20

                                          @TindrasGrove

                                          It is cruel to require senior citizens on severely limited incomes to have cell phones & email accounts.

                                          1 Reply Last reply
                                          0

                                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                          With your input, this post could be even better 💗

                                          Register Login
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post