←back to thread

184 points Bogdanp | 2 comments | | HN request time: 0s | source
Show context
juancn ◴[] No.45106230[source]

    Signing into my accounts on my children’s devices has turned from a straightforward process to an incredibly frustrating experience. I find myself juggling all kinds of different apps and flows.
This strikes home for me, I'm the main gatekeeper of passwords and service accounts in my home. 2FA and passkeys are so annoying to juggle.

My kids use prepaid numbers, once I changed one and forgot to tell Apple, when I realized that I needed the old number later, it took me a month at least to get it back.

I really like passwords, the security risks are well known and really easy to handle compared to 2FA and all that crap, specially when 99% of your accounts are not sensitive enough to merit anything fancy.

replies(5): >>45106514 #>>45106530 #>>45107602 #>>45108644 #>>45112401 #
toomuchtodo ◴[] No.45106514[source]
Passwords are a weak authentication mechanism and incur liability. MFA is good, Passkeys are better. One time passwords via email are tolerable, still better than passwords.

(customer identity and access management is a component of my work at a fintech)

replies(3): >>45106589 #>>45106861 #>>45111579 #
OJFord ◴[] No.45106861[source]
Your fintech is probably not among the 99% accounts GP says don't warrant 'anything fancy'.

IME as a customer/user, financial institutions are some of the worst culprits for doing appalling things in the name of security (theatre) anyway.

replies(2): >>45106946 #>>45107024 #
tadfisher ◴[] No.45106946[source]
Yes, because financial institutions are responsible for losses incurred via account takeover.
replies(2): >>45106984 #>>45109666 #
1. jazzyjackson ◴[] No.45109666[source]
And yet they are still out here offering voiceprint authentication
replies(1): >>45110538 #
2. toomuchtodo ◴[] No.45110538[source]
JP Morgan Chase does this, regrettably.