Hacker Newsnew | past | comments | ask | show | jobs | submit | mrguyorama's commentslogin

That they have purposely put effort into preventing you from doing that shows you everything you should need to know.

The entire point of passkeys is yanking the control over authentication out of the hands of people. These companies don't want you to be able to let someone else log in as you.

That's the entire point.

The problem they are solving has absolutely nothing to do with security.


Yes, that is what everyone keeps complaining about and the people who insist passkeys are the best continue to loudly and totally ignore.

The repeated response to "I lost the passkey, what now?" is apathy. It is your fault, you should have done better, eat it loser.

Because companies built passkeys for their own needs, not for users. In a managed device setting, there is a response: You go to IT and get provisioned new credentials. These companies don't care that you get fucked because they just don't care about your needs at all.


No, microsoft uploading disk encryption keys to your account is the exact opposite situation. It's microsoft purposely reducing security to ensure there is a recovery path, because average people don't need or want the security tradeoffs where "You permanently lose access and it mathematically cannot ever be recovered" is a failure mode.

If it was possible for a key to your house to have that failure mode, nobody would ever lock their doors


A recovery path that is taken from you if you forget your Microsoft account password or your account gets banned on a whim. Sure.

The entire problem with passkeys is that zero of the issues should have been a surprise, because it should have been part of the design discussion from the start, so the fact that it's not properly implemented before being forced on users says that either it's been done horrifically incompetently and nobody should trust it, or they internally found these concerns and ignored them which means this system is not at all meant to help us, so why is it being forced on us?

That any and all physical security measures can be defeated is a feature, not a bug. Almost no human beings actually need that level of security, and the tradeoffs are absolutely not worth it for those of us without Mossad as a threat.

How often do people lock themselves out of their own house? Don't you know anyone with ADHD? Imagine any time that happens it is mathematically verifiably permanent as a fact of reality itself. It doesn't matter that the state still views you as the legal owner, you are never allowed in ever again.


No web service is like that. They all offer recovery options. We aren't talking about Bitcoin here.

The trend of companies becoming easier to contact and customer service becoming better is well-documented.

Tell that to the people who have lost access to their Google account.

This is called college.

Broadly, universities are too expensive, inequitable, suboptimal, not portable, and slow. There's a huge amount of room for improvement.

Universities are great for networking, starting projects with other students (not the ones professors mandate), and learning lab sciences. In research, they're great for institutional knowledge, having a community of peers, getting guidance from research advisors, having real equipment and funding, etc. But there's a great need for AI tools to accelerate learning outside of that setting.

Anecdotally, I'm a working adult. I'm not going to waste time in college again. I need this for me.


>USG is under no obligation to have up to date information.

Why not? This is not the perspective of the various international agreements the US has signed about war. Knowing what you are shooting is in fact an obligation.

Hell, knowing what you are shooting is an obligation of deer hunters in my state. If you shoot someone because you thought they were a deer, you are in trouble even if they weren't wearing an orange vest.

The reason this obligation exists is because you always have the option to not shoot. If you do not know accurate info about what you are shooting at, you are supposed to not shoot at it.


Hegseth said loud and clear that they wouldn't be a pussy ass weak ass bitch ass military anymore.

What the hell do you think he meant by that? Because this is the exact thing he meant by that.

Note that this kind of "Double tapping" was commonly done in strategic bombing in WW2! It's done because it's a very effective thing to do! Or at least, it usually is if you have an actual plan and strategy.


Google actually puts effort into security for "normal" people who don't want to earn a PhD in cryptography just to have a damn free email account or watch Mr. Beast

That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador.

Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email


The best backup method doesn't need any computer knowledge, it's writing down or printing a few passwords and putting that piece of paper in the same box as your taxes or birth certificate.

You have. That airship's maiden voyage was in 2012. The US DoD has pretty much never stopped throwing a few dollars at airship projects. They want them as long term air reconnaissance assets, but now satellites are competitive for that.

Former Loring Air Force base in Limestone Maine has been the home of airship projects of various kinds since the 2000s. I got to see a few.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: