I’m gonna need everyone in security to internalize this.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove while I support 2FA, passkeys, etc for security reasons, this goes to show that smartphones and certain essential softwares should be accessible and affordable/free to all.
We made everything more accessible through digitalization, but handed the key to the gate to a select few corporations, hiking prices and excluding those that just want to participate, but lack the will or funds to do so.
-
@TindrasGrove while I support 2FA, passkeys, etc for security reasons, this goes to show that smartphones and certain essential softwares should be accessible and affordable/free to all.
We made everything more accessible through digitalization, but handed the key to the gate to a select few corporations, hiking prices and excluding those that just want to participate, but lack the will or funds to do so.
@TindrasGrove I should add: lack the will or funds to acquire the necessary tools. Especially for elderly folk it should only take the will to adopt the new tech and learn the use of it - it shouldn’t come with a pricetag of several hundred dollars & monthly subscription.
-
@darkcat09 @TindrasGrove an attacker may well only have an email and a password from a leak somewhere and is trying to see if they can score a breakin from a password reuse
-
@mirabilos @ajn142 Your password manager should detect that you're on the wrong site, and shouldn't offer auto-fill at all.
-
@darkcat09 @TindrasGrove Sure it does, SMS slightly more than e-mail (as it's a different channel entirely) – both will prevent password spray attacks, which is good enough for 90% of people.
They won't stop targeted attacks, but those aren't a concern for majority of people.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove Also, in the UK landline phones are being switched off. They can only be used via a broadband router.
-
@TindrasGrove Also, in the UK landline phones are being switched off. They can only be used via a broadband router.
@oldrawgabbit @TindrasGrove Although, hilariously, my landline was supposed to be turned off this week and turned into a VoIP service. But *on the day*, I got an email from VirginMedia saying "Oopsie, we're delaying this indefinitely. Just store the adaptor we sent you in a drawer somewhere." How badly do you have to have messed up the planning on a migration like this to have to cancel at the last minute? 😱
-
@tknarr @TindrasGrove SMS, email, and other "less secure" 2fa methods are far from useless. They prevent untargeted attacks. If your threat profile includes a persistent attacker going after you specifically, sure they are insufficient, but that isn't a reasonable threat profile for a vast majority of accounts on any service.
@danielleigh @TindrasGrove No, they don't protect from untargeted attacks. Someone scanning eg. Paypal logins looking for vulnerable ones will have the phone number associated with it. They don't have to be targeting a specific person to look up the carrier info for that phone number and clone the SIM. Email is a little harder if you use a client, but webmail is vulnerable to standard browser compromises.
-
I’m gonna need everyone in security to internalize this.
Hell, my local country fair (y’know, the place where you can submit your veggies to go on display and get judged and get ribbons and shit) is requiring online registration.
Guess how many people that’s locking out? How many of the people whose submissions are what keep the exhibitions going don’t have emails or cell phones?
If your solution doesn’t work for my friend who can only be reached via landline phone or mail, it doesn’t work.
@TindrasGrove I’ve been working in this space for 20+ years. I agree more of us need to see cases like this. They are not corner cases. They are significant numbers of people in large populations and have to be considered when we design authentication systems. Thanks for sharing this.
-
I think about 95% of adults in wealthy countries have a smart phone
So about 95% have access to online registration ?
of th remaining 5% a lot are grouches like me, I don't have a smartphone but can obviously can use the internet
of the remaining what, 1% of adults who don't have a smartphone or a laptop, maybe 50% can access these things at a library ?
roughly ?
very few systems work smoothly for the last half percet
@failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.
-
@rickf @TindrasGrove I understand that & what I am saying is: this already challenging enough - they shouldn’t have to commit to costs to participate or use basic services on top of everything else.
But as digitalization progresses, access becomes essential and you are forced to pay for it.
I’m addressing a different angle to the topic as well, so to say. In no way am I invalidating the statement.
-
@failedLyndonLaRouchite @TindrasGrove the last half percent is still a huge number of people.
absolutely
but as I tried , and possibly failed, to say, it is very hard to design systems that work well for the half percent -
@rickf @TindrasGrove sorry - I got a pretty hateful reply (which was deleted shortly after), so I felt a bit defensive.
-
@alxndr @derAndereAndre @TindrasGrove My grandma would be a lot more secure if she simply did not need a smartphone. There is no version of the technology that would be appropriate for her as her mind ages.
Ideally her home would have a small computer lab for those few computer tasks, and she would spend more of her time offline.
What I am saying is "We need to stop pressuring everyone to have a fucking smartphone"
-
@TindrasGrove Most of us have. We've also internalized a fact from experience: anything _not_ using some form of 2FA will be compromised within a couple of months, and the owner _will not_ be able to recover from it. If you use a public computer make that a week, tops, and likely less than 24 hours. Some forms of 2FA, like SMS or voice call or email, are useless because they're so easy to compromise. The only reliable ones I know of are TOTP or an authenticator app (passkey) on a smartphone, ...
@tknarr @TindrasGrove But if we're talking about registration for an event that is probably at most three weeks away...
Why not use a 2fa that can be breached within months? The event will be over by then anyway, so you can just close down that account.
-
@patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.
Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.
-
@patrizia @TindrasGrove Passkeys deeply terrify me due to the unchecked assumptions and requirements.
Like we should never assume a users device will always be accessable, reliable, and always owned by an individual.
@Epic_Null @patrizia I am right there with you!
For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.
For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.
-
@Epic_Null @patrizia I am right there with you!
For my corporate work stuff where if they fail, I can have my manager verify my identity to the help desk to do a reset? Fine.
For things like my personal email where there’s not a way for me to reach someone who will reset? Fuuuuuuuuccckk noooo!!! The failure mode is just too much for me.
@TindrasGrove @patrizia Yeah a LOT of tech I have a problem with is forcing tech for corporarions onto home users.
This stuff has risks PERFECTLY managable with a functioning IT department, but disasterous for home users.
Bitlocker is a perfect example of this.
Security advocates model your threats challenge.
-
K Kichae crossposted this topicto General on
-
K Kichae moved this topic from World
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login