zlacker

[parent] [thread] 21 comments
1. aetern+(OP)[view] [source] 2025-11-13 17:57:08
I'm not sure this is very fair because humans are often not given the right tools to make a good decision. For example:

To gift to a 529 regardless of the financial institution, you go to some random ugift529.com site and put in a code plus all your financial info. This is considered the gold standard.

To get a payout from a class-action lawsuit that leaked your data, you must go to some other random site (usually some random domain name loosely related to the settlement recently registered by kroll) and enter basically more PII than was leaked in the first place.

To pay your fed taxes with a credit card, you must verify your identity with some 3rd party site, then go to yet another 3rd party site to enter your CC info.

This is insane and forces/trains people to perform actions that in many other scenarios lead to a phishing attack.

replies(3): >>theweb+Tj >>aidenn+X41 >>maest+F42
2. theweb+Tj[view] [source] 2025-11-13 19:26:04
>>aetern+(OP)
Don't forget magic links in email for auth and password resets training people that it's OK to click links in emails.

Yes, we've (the software industry) been training people to practice poor OpSec for a very long time, so it's not surprising at all that corporate cybersecurity training is largely ineffective. We violate our own rules all the time

replies(3): >>wholin+pr >>Razeng+Cv >>Sophir+mc2
◧◩
3. wholin+pr[view] [source] [discussion] 2025-11-13 20:06:50
>>theweb+Tj
Has anyone invented an alternative to that yet? I could imagine emailing you a code to enter in a specific part of a site to get you to the right link, but then people could just scan all the codes. To solve that you could make the codes long 64bit strings but then that's too hard to remember so you could just provide functionality to automatically include that info to get you to the site but then that's just a link again.

Maybe if you expected everyone to copy-paste the info into the form? That might work

replies(3): >>aetern+lv >>miiiii+0v1 >>kakaci+g82
◧◩◪
4. aetern+lv[view] [source] [discussion] 2025-11-13 20:28:20
>>wholin+pr
This is the closest I've seen (pretty new): https://github.com/WICG/email-verification-protocol
replies(1): >>rapind+cw1
◧◩
5. Razeng+Cv[view] [source] [discussion] 2025-11-13 20:29:57
>>theweb+Tj
There should be a way to tell you who I am without telling you who I am.

Phone/laptop based biometrics?

replies(5): >>theweb+EO >>disill+U21 >>edoceo+Sq1 >>Brian_+VC1 >>dredmo+LB2
◧◩◪
6. theweb+EO[view] [source] [discussion] 2025-11-13 22:08:18
>>Razeng+Cv
I think this is the way forward. We shouldn't continue relying on email (or proving ownership over an email address for that matter) as identity.

Public/private keys with a second factor (like biometrics) as identity I think is a good option. A way to announce who you are, without actually revealing your identity (or your email address).

Tbh that's how all the age verification crap should work too for the countries that want to go down that road instead of having people upload a copy of their actual ID to some random service that is 100% guaranteed going to get breached and leaked.

We need psuedoanonymous verification

◧◩◪
7. disill+U21[view] [source] [discussion] 2025-11-13 23:39:25
>>Razeng+Cv
Isn't that what a passkey is intended to be?

If I want to use a passkey on my phone, I have to bio authenticate into it. Similarly, with Windows Hello as a passkey provider, via my camera scanner. It works well and is pretty seamless, all things considered. I prefer it to the email/code/magic link method.

replies(1): >>DANmod+ED1
8. aidenn+X41[view] [source] 2025-11-13 23:58:50
>>aetern+(OP)
Don't forget credit checks when you apply for an apartment! "Go to this website sent via e-mail from someone you only know through a craigslist ad and enter all of your PII. On top of that about 2/3 of what is listed actually is phishing attempts and good luck telling the difference"
replies(1): >>DANmod+JD1
◧◩◪
9. edoceo+Sq1[view] [source] [discussion] 2025-11-14 03:52:56
>>Razeng+Cv
pGP signature?
replies(1): >>dredmo+aC2
◧◩◪
10. miiiii+0v1[view] [source] [discussion] 2025-11-14 04:41:24
>>wholin+pr
It’s easier/more complicated than that. Use 6 digit codes, tied to a specific reset session, with only 3 attempts allowed per-session, and sessions lasting only 5 minutes.
◧◩◪◨
11. rapind+cw1[view] [source] [discussion] 2025-11-14 04:52:23
>>aetern+lv
I recently discovered that Microsofts SSO doesn't guarantee email veracity. Basically you can spoof emails via ActiveDirectory, so if a site supports Microsoft's SSO and doesn't do a second verification, then someone could login to your site with someone else's email.

I mean, what's the point of their SSO if you're just going to need to verify it with an email code anyways?

◧◩◪
12. Brian_+VC1[view] [source] [discussion] 2025-11-14 06:22:50
>>Razeng+Cv
The mechanics are a solved problem by sqrl I think, but it's too much responsibility for basically everyone.

You really do fully own and control your identity, and if you botch it and lose your top level keys, no one else can give you a "forgot password" recovery.

If this level of unforgiveness were dropped onto everyone overnight, it would mean infinite lost life savings and houses and just mass chaos.

Still I think it would be the better world where that was somehow actually adopted. The responsibility problem would be no problem if was simply the understood norm all along that you have this super important thing and here is how you handle it so you don't lose your house and life savings etc.

If you grew up with this fact of life and so did everyone else, it would be no problem at all. If it had been developed and adopted at the dawn of computers so that you learned this right along with learning what a compuer was in the first place, no problem. It's only a problem now that there are already 8 billion people all using computer-backed services without ever having to worry about anything before.

The real reason it's never gonna happen is exactly because it delivers on the most important promise of end user ultimate agency and actual security.

No company can own it, or own end users use of it. It can not be used for vendor lock in or data collection or profiling or government back doors or censorship or discrimination or any of the things that holding someone's password or the entire auth technology can be used for to have control over users.

No (large) company nor any government has any interest in that, and it's way too technical for 99.99% of people to understand the problems with all the other popular auth systems so there will be no overwhelming popular uprising forcing the issue, and so it will never happen.

A method already exists (I think), that solves the hard problems and delivers the thing everyone says they want, and everything else claims to be groping for, but we will never get to use it.

◧◩◪◨
13. DANmod+ED1[view] [source] [discussion] 2025-11-14 06:29:20
>>disill+U21
It’s how I’ve been using physical keys over the same protocol for years, mhmm.
◧◩
14. DANmod+JD1[view] [source] [discussion] 2025-11-14 06:31:05
>>aidenn+X41
If you apply to living spaces before viewing after emailing or calling,

well, no wonder they’re after you as a demographic.

replies(1): >>aidenn+xY3
15. maest+F42[view] [source] 2025-11-14 12:24:54
>>aetern+(OP)
This is very much a US issue, largely because the government outsources everything to the private sector. This proliferation of random websites and shady 3rd parties is one of the consequences of this.
◧◩◪
16. kakaci+g82[view] [source] [discussion] 2025-11-14 13:03:39
>>wholin+pr
Don't allow HTML rendering of <a> element where href links to another URL than shown, don't allow any (java)scripts to run, or at least give user a warning that he is about top open a new window into domain XYZ.

This is how I found out quite a few scams (apart from obvious ones with improper wording or visual formatting, but those are on purpose so bad to catch only most unskilled or gullible, ie your grandma)

◧◩
17. Sophir+mc2[view] [source] [discussion] 2025-11-14 13:38:16
>>theweb+Tj
About 10 years ago, I got an email from Microsoft of all people(!) which to any reasonably security-trained person would look entirely like a phishing email:[0]

1. It said "Dear User" instead of a name/username;

2. It talked about how they were upgrading their forum software and as such would require me to re-login;

3. It gave me a link to click in the email without any stated alternative;

4. It warned me that if I didn't do this, I would no longer be able to access the forum;

5. The domain of the URL that the link went to was not microsoft.com, but a different domain that had "microsoft" in it.

It was a textbook example for how a phishing email would look, and yet it was actually a legitimate email from Microsoft!

I haven't had any others like it since, but that was an eye-opener for sure.

[0] https://reddit.com/r/facepalm/comments/32ou4z/microsoft_what...

[Edit: Fixed a detail I misremembered.]

◧◩◪
18. dredmo+LB2[view] [source] [discussion] 2025-11-14 16:03:55
>>Razeng+Cv
Biometrics might be useful in establishing a (PKI) key, but are not suitable for the key itself.

"Something you have" is far more useful, especially if that something is itself cryptographically-based. Yubikeys, RSA fobs (generating one-time codes), and wearable NFC tokens (rings, amulets), and the like, which may be autheticated in part based on biometrics and other attestation, but are themselves revokable, would be a far better standard.

What the General Public can be expected to utilise willingly and effectively seems to be the larger problem, as well as what commercial and governmental standards are established.

◧◩◪◨
19. dredmo+aC2[view] [source] [discussion] 2025-11-14 16:05:57
>>edoceo+Sq1
An unblemished 34 year record of failing mainstream adoption.

(I've had at least one PGP/GPG key for the past quarter century or so myself.)

◧◩◪
20. aidenn+xY3[view] [source] [discussion] 2025-11-14 23:31:02
>>DANmod+JD1
Like when you suddenly have to move to a different city due to an unexpected job change and are trying to schedule as many viewings in one weekend as possible?
replies(1): >>DANmod+Zn4
◧◩◪◨
21. DANmod+Zn4[view] [source] [discussion] 2025-11-15 04:12:52
>>aidenn+xY3
Job asks me for a start date, I tell them tomorrow - if remote,

or a month.

Sooner, if they help with relocation.

replies(1): >>aidenn+SS5
◧◩◪◨⬒
22. aidenn+SS5[view] [source] [discussion] 2025-11-15 21:33:58
>>DANmod+Zn4
I'm guessing this isn't a job that pays $15 per hour...
[go to top]