• 1 Post
  • 92 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle
  • This is a good question. Phone numbers are increasingly used as de-facto ID numbers, everywhere in the world. That’s because, unlike email, they cost money, and in most jurisdictions you can’t even get one anymore without presenting real ID. So: if you have a second phone number, you can effectively have a second persona for any site or app that requires phone-number ID. Seriously, at this rate, it’s going to be all of them.

    IMO the best use-case for this is to quarantine your contact list. That is, keep a separate number for social networks and messaging. The number you give to your in-person contacts will be instantly shared with all their cloud services, whether you like it or not. This is what allows Big Tech to triangulate and discover exactly who you know and therefore who you are. If the cloud services cannot trace a number back to any phone ID in their own books, then they can’t do much with it and you will remain at least something of a mystery to them.






  • Literally “always”, like every single time you open a website or app? No password manager can make SMS 2FA not a PITA. As for your second point, I addressed that. What if you literally don’t care about keeping data in question private? Individuals have different threat models, different priorities and all of this is a trade-off. It’s not absolute. That’s all I was saying. Anyway, I’m done here.


  • Yes this clarifies things. In summary, without 2FA:

    • use a strong password unique to that site (i.e., via a credentials manager) - safe except on that site if absolute morons are running it
    • use a weak password unique to that site - safe elsewhere
    • use weak passwords and recycle them - you are in trouble

    So it’s a trade-off. If everyone was in the first category, then the obvious inconvenience of 2FA would just not be worth the benefit.


  • If the password is unique, there’s no risk!

    Incidentally: not re-using passwords should be the only responsibility of the user. It’s impossible to brute-force a password through a login form, you need full access to the disk. So when sites complain about poor password strength, effectively they are saying “We don’t trust ourselves to keep our server safe”. Pretty insulting to blame the user for that.





  • Which begs the question, “What is FIDO?”. To which the About FIDO page replies, literally, “FIDO authentication uses standard public key cryptography techniques to provide phishing-resistant authentication”.

    Arrghghgh! Orwell was right about people’s incredibly capacity to write with zero clarity.

    More generally, IMO what we have here is a classic case of ELI5 vs “ELI know something already”. I use SSH and manage the keys myself but I still can’t find an answer to this question: is a “passkey” just another word for “the private key in a public-private keypair?”

    Whenever I look into this, the explainer always either jumps straight into super-dense technical details, or describes it all in term of metaphors as if talking to a small child. Oh well.








  • Sure. I personally find cynicism intensely irritating. It’s infectious so it inevitably ends up poisoning everything. Nobody ever solved any problem with cynicism. In fact I’d go further: all the world’s backward societies (i.e. most of them) are characterized by all-pervasive cynicism (“they’re in it for themselves”, “they’re all crooks”, “nothing will ever change”), whereas the successful countries (few in number) are the ones where people have a more optimistic view of others’ motives. Cynicism is so obviously a self-fulfilling prophesy that I struggle to understand why so many choose to indulge it. I’ve heard a theory that it makes people feel better about their own helplessness. Perhaps I’m too logical but I wish people would choose not to wallow in pessimism - after all, nobody can prove anything one way or the other when it comes to the motivations of others. And oddly, most humans tend to trust others that they know personally. Personally don’t see why strangers would somehow be a different variety of human. Rant over.