(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43398692

Hacker News 的讨论围绕着在线账户安全以及不同身份验证方法的有效性展开。最初的评论指出密码重用是一个主要漏洞,强调即使是强密码,如果从其他服务泄露,也会变得毫无用处。它提倡使用独特的密码、密码管理器或双因素身份验证 (2FA)作为解决方案。随后的评论批评了依赖电话号码或专有应用程序进行 2FA 的做法,更倾向于使用 TOTP 以获得更大的用户控制权和隐私。讨论随后转向密钥,承认它们有可能消除与密码相关的各种问题,但也对单点故障、供应商锁定以及对不太懂技术的用户的可访问性表示担忧。最后,一位用户指出,即使是记住的复杂密码,如果没有启用 2FA,仍然容易受到键盘记录器的攻击。

相关文章
  • (评论) 2025-03-18
  • (评论) 2024-06-10
  • (评论) 2024-04-27
  • (评论) 2025-03-09
  • 启用双因素身份验证 (2FA) 还是不启用? 2025-03-20

  • 原文
    Hacker News new | past | comments | ask | show | jobs | submit login
    2FA or Not 2FA (mova.org)
    3 points by sam_lowry_ 1 hour ago | hide | past | favorite | 4 comments










    Password re-use is the bigger issue.

    No one can crack your super-strong multilingual password. But if a service accidentally leaks it, then it doesn't matter.

    Credential Stuffing is how 23andMe were hacked. People reused password, they were leaked from another service, attackers tried them on a variety of sites until they hit the jackpot.

    Unique passwords prevent that attack. Can't remember a thousand different passwords? Use a manager.

    Don't want to use a manager? Switch on 2FA. Weak passwords and password reuse ceases to be a problem.

    Yes, as the article points out, it slightly reduces ease of login. But that seems like a sensible trade off.



    Plus many want your phone number or some random app by them on your phone for their 2FA (instead of e.g. TOTP that you contol), less secure because they now can leak your phone number or do something with an update to the app

    BTW what's the sentiment on passkeys?



    In my opinion passkeys, whilst solving the password related issues, introduce their own. The risk of losing access to your accounts is greater if you tie everything to one device and that's lost or stolen, and the "solution" to use more than one device is not a solution, or feasible for everyone. There's also the risk of vendor lock-in, which is definitely an aim of the big providers like Apple, Google and Microsoft; which is a bigger risk to those less tech savvy.


    lol

    >One of the passwords that I know by heart is a famous classic quote clumsily translated in a mix of French and Dutch. It is long, it can not be brute-forced because of its length and I am pretty sure it is not present in any of the rainbow tables. I never spell it out, let alone write it down, but it is in my muscle memory as I haven't changed it for years.

    One keylogger and his super complex and secure password is ruined. with no 2FA to protect him.







    Join us for AI Startup School this June 16-17 in San Francisco!


    Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



    Search:
    联系我们 contact @ memedata.com