I’m gonna need everyone in security to internalize this.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
-
R AodeRelay shared this topic on
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
I think about 95% of adults in wealthy countries have a smart phone
So about 95% have access to online registration ?
of th remaining 5% a lot are grouches like me, I don't have a smartphone but can obviously can use the internet
of the remaining what, 1% of adults who don't have a smartphone or a laptop, maybe 50% can access these things at a library ?
roughly ?
very few systems work smoothly for the last half percet
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove It seems to me the appropriate form of two factor for an in person event would be... an in person item. Like a physical piece of paper.
-
P Pteryx the Puzzle Secretary shared this topic on
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Kind of thing which also often makes me wonder what happens if someone looses their phone and they got all their sms/2fa stuff in it.
Wouldn't even be surprised that it would be a struggle to buy a new sim card, and well last time I bought a cellphone they wanted the number for the delivery (usually to ping beforehand or in case bell/intercom doesn't works). -
@mirabilos @TindrasGrove I agree with the general point of usability (and accesibility!) over security.
But 2fa does improve security, a lot. Some studies show that it reduces hacks by over 90%
-
@mirabilos @TindrasGrove even devices forcing a PIN or passcode is bullshit. I'm looking at you, iPad, that never leaves the grandparents house.
-
@TindrasGrove Kind of thing which also often makes me wonder what happens if someone looses their phone and they got all their sms/2fa stuff in it.
Wouldn't even be surprised that it would be a struggle to buy a new sim card, and well last time I bought a cellphone they wanted the number for the delivery (usually to ping beforehand or in case bell/intercom doesn't works).@lanodan I would rather lose my wallet than my phone.
-
@mirabilos @TindrasGrove grandma doesn't need encryption at rest either lol
-
@mirabilos except if you log in on a device with a stealer or force your password manager to fill on a phishing site, 2FA prevents persistent access to your account. And yeah, for everything except the critical stuff I store my TOTP in the same password manager as the user/password credentials, but for those few critical systems (including my email and password manager), I have separate factors.
Too many systems make it mandatory when they shouldn’t, or only support factors that make it nearly moot (looking at you, email/SMS OTP). But saying it adds nothing but inconvenience ignores a whole lot of threats that it complicates or outright prevents
-
@mirabilos except if you log in on a device with a stealer or force your password manager to fill on a phishing site, 2FA prevents persistent access to your account. And yeah, for everything except the critical stuff I store my TOTP in the same password manager as the user/password credentials, but for those few critical systems (including my email and password manager), I have separate factors.
Too many systems make it mandatory when they shouldn’t, or only support factors that make it nearly moot (looking at you, email/SMS OTP). But saying it adds nothing but inconvenience ignores a whole lot of threats that it complicates or outright prevents
@ajn142 @mirabilos really don't think anyone has actually said that 2fa never has any practical use case beyond making things inconvenient. What was said is that for many people it completely removes them from an increasing number of aspects of normal public life that they should be entitled to participate in as a bare human being without being required to have a mobile device or computer to have access.
-
@ajn142 @mirabilos really don't think anyone has actually said that 2fa never has any practical use case beyond making things inconvenient. What was said is that for many people it completely removes them from an increasing number of aspects of normal public life that they should be entitled to participate in as a bare human being without being required to have a mobile device or computer to have access.
That’s more like 10 than 15 seconds, and in no way an increase in security.
From the post I was replying to :)
-
@TindrasGrove @lanodan as someone who has their phone smashed to an inoperable state, it left me very isolated for the 4 days I was in the ICU until I could get back to my home wifi to MFA back into my account, even with a highly trusted person clicking the 2FA auth for my Google account, it still denied my log in because the auth and 2fa were too far apart 🙃
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Precisely. Locking people out by not providing accessibility is a bad idea as-is, but forcing the usual "Banking-App DRM" etc. is a worse idea. It's not about "Haha, you don't own a phone!", reader! Batteries and internet limits exist!
-
@TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
@TindrasGrove ... a hardware key (eg. Yubikey), or a printed list of auth codes.
No, we don't like it any more than you do. Thank the swill-licking bargepole-swallowers who try to attack anything and everything just for kicks, and the even scummier crooks who pay them for credentials.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Not to mention the non literate being excluded.
-
@mirabilos correct, but best practice is that when changing security information such as password, email, or adding another 2FA factor you’d need to authenticate again, including 2FA. So while it won’t stop the account from being accessed or abused, it does help prevent takeover. I was specific about persistent access there for a reason.
Also protects against credential stuffing in the case of reused passwords, which is likely a bigger risk to the average person.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Most things should be able to be done offline.
The burden obviously falls disproportionately on the poor, immigrants, illiterate, elderly or disabled. But also a surprising amount of people simply feel alienated by online services.
I think it would be helpful if more people who are more privileged chose to do things offline where possible. It makes it easier for companies and the government to justify the expense for people who are marginalised.
-
@TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
@tknarr @TindrasGrove SMS, email, and other "less secure" 2fa methods are far from useless. They prevent untargeted attacks. If your threat profile includes a persistent attacker going after you specifically, sure they are insufficient, but that isn't a reasonable threat profile for a vast majority of accounts on any service.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
It is cruel to require senior citizens on severely limited incomes to have cell phones & email accounts.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login