Tell HN: Internet companies sabotaging password managers

https://news.ycombinator.com/item?id=42880304
by figassis • 1 year ago
3 2 1 year ago

Not too long ago, everyone started putting users through authentication hell in favor of requiring 2FA. I settled on 1Password.

Setting aside the "2FA on same storage as passwords" argument, this flow is pretty secure. One password per service and TOTP codes work well, especially because the app locks itself within minutes, requires biometric unlocking and requires a password every X weeks.

But now, big tech apps prioritize (and often require) their non deterministic 2FA flows.

Google makes you login via any Google app you're logged in as (sometimes that is a desk clock). You need to hunt down the hidden option to use your 2FA app.

With Stripe, some operations require a passkey or "Email + 2FA Authenticator". Seems the email part is just to create friction.

There are many other cases where they treat regular 2FA the same as "password123". Is the goal here just to sell everyone on passkeys?

Related Stories

Loading related stories...

Source preview

news.ycombinator.com