Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #275727 > unrolled thread

a passwordless operating system

Started by🦓 <czyborra@gmail.com>
First post2024-12-15 09:00 +0100
Last post2024-12-16 09:20 +0100
Articles 8 on this page of 68 — 23 participants

Back to article view | Back to linux.debian.user


Contents

  a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
    Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
      Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
        Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
          Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
            Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
              Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
            Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
              Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
              Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
                  Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
                    Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
            Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
              Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
                Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
                  Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
                    Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
                      Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
                          Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
                              Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
                          Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
                            Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
                        Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                      Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
                          Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
                            Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
                            Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
                              Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
                                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
                                Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
                                  Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
                                  Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
                              Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
                  Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
                    Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
                      Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
                    Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                      Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
                      Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
                  Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
              Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
              Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
                Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
        Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
    Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
        Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
          Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
            Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
          Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
            Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
        Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100

Page 4 of 4 — ← Prev page 1 2 3 [4]


#275737

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-15 15:40 +0100
Message-ID<JTXWN-hdGo-3@gated-at.bofh.it>
In reply to#275727
On Sun, Dec 15, 2024 at 6:47 AM 🦓 <czyborra@gmail.com> wrote:
>
> my mother is currently struggling to memorize all of my dead stepfather's identities and passwords and that makes me wonder how would you like an internet of hosts who store everything undeletably and barrierlessly readably with no secrets whatsoever to humanity nor any other natural or artificial or divine intelligence?   i know this sounds like a question for debian-devel or debian-policy but i m dumping it onto debian-user as as of now i m not subscribed to any other.

For some of the larger sites you can use a YubiKey. YubiKeys use the
FIDO/FIDO2 protocols. I believe WebAuthn also supports YubiKeys.

But I found a lot of sites do not support FIDO/FIDO2 protocols. For
example, most banks and my mother's credit union do not support them.
In this case, I send a letter to the company's legal department and
put them on notice. (I also point out the problems with their current
authentication system).

If you start switching to YubiKeys, then be sure to use two of them.
The second is a backup YubiKey, and it also gets enrolled when you
convert the account. The backup YubiKey is used in case the first
YubiKey is lost.

Jeff

[toc] | [prev] | [next] | [standalone]


#275755

From🦓 <czyborra@gmail.com>
Date2024-12-16 08:50 +0100
Message-ID<JUe1z-hujU-1@gated-at.bofh.it>
In reply to#275737

[Multipart message — attachments visible in raw view] — view raw

YubiKeys is a password manager in a dongle, thus the exact opposite of
passwordless.  Your dogs and your goats are passwordless, they reliably
serve you but have a built in immune system with redundancies protecting
them from abuses of their passwordlessness.

Op zo 15 dec 2024 om 15:35 schreef Jeffrey Walton <noloader@gmail.com>:

> On Sun, Dec 15, 2024 at 6:47 AM 🦓 <czyborra@gmail.com> wrote:
> >
> > my mother is currently struggling to memorize all of my dead
> stepfather's identities and passwords and that makes me wonder how would
> you like an internet of hosts who store everything undeletably and
> barrierlessly readably with no secrets whatsoever to humanity nor any other
> natural or artificial or divine intelligence?   i know this sounds like a
> question for debian-devel or debian-policy but i m dumping it onto
> debian-user as as of now i m not subscribed to any other.
>
> For some of the larger sites you can use a YubiKey. YubiKeys use the
> FIDO/FIDO2 protocols. I believe WebAuthn also supports YubiKeys.
>
> But I found a lot of sites do not support FIDO/FIDO2 protocols. For
> example, most banks and my mother's credit union do not support them.
> In this case, I send a letter to the company's legal department and
> put them on notice. (I also point out the problems with their current
> authentication system).
>
> If you start switching to YubiKeys, then be sure to use two of them.
> The second is a backup YubiKey, and it also gets enrolled when you
> convert the account. The backup YubiKey is used in case the first
> YubiKey is lost.
>
> Jeff
>


-- 
+491601449986@linktr.ee/czyborra🦓

[toc] | [prev] | [next] | [standalone]


#275756

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-16 08:50 +0100
Message-ID<JUe1z-hujU-3@gated-at.bofh.it>
In reply to#275755
On Mon, Dec 16, 2024 at 2:42 AM 🦓 <czyborra@gmail.com> wrote:
>
> YubiKeys is a password manager in a dongle, thus the exact opposite of passwordless.  Your dogs and your goats are passwordless, they reliably serve you but have a built in immune system with redundancies protecting them from abuses of their passwordlessness.

You don't understand YubiKeys, their capabilities, and Universal
Second Factor. The security requirements of U2F are a token that has:

    1. high entropy
    2. replay resistant
    3. phishing resistant

Passwords may satisfy (1), but they completely fail at (2) and (3).

And your original problem statement stated memorization was the
problem you were trying to solve. Even if a YubiKey serves up a fixed
password (which it does not), then it solves your memorization
problem.

I have no idea what dogs and goats have to do with things.

Jeff

> Op zo 15 dec 2024 om 15:35 schreef Jeffrey Walton <noloader@gmail.com>:
>>
>> On Sun, Dec 15, 2024 at 6:47 AM 🦓 <czyborra@gmail.com> wrote:
>> >
>> > my mother is currently struggling to memorize all of my dead stepfather's identities and passwords and that makes me wonder how would you like an internet of hosts who store everything undeletably and barrierlessly readably with no secrets whatsoever to humanity nor any other natural or artificial or divine intelligence?   i know this sounds like a question for debian-devel or debian-policy but i m dumping it onto debian-user as as of now i m not subscribed to any other.
>>
>> For some of the larger sites you can use a YubiKey. YubiKeys use the
>> FIDO/FIDO2 protocols. I believe WebAuthn also supports YubiKeys.
>>
>> But I found a lot of sites do not support FIDO/FIDO2 protocols. For
>> example, most banks and my mother's credit union do not support them.
>> In this case, I send a letter to the company's legal department and
>> put them on notice. (I also point out the problems with their current
>> authentication system).
>>
>> If you start switching to YubiKeys, then be sure to use two of them.
>> The second is a backup YubiKey, and it also gets enrolled when you
>> convert the account. The backup YubiKey is used in case the first
>> YubiKey is lost.

[toc] | [prev] | [next] | [standalone]


#275757

FromAndy Smith <andy@strugglers.net>
Date2024-12-16 09:00 +0100
Message-ID<JUebf-hunB-7@gated-at.bofh.it>
In reply to#275756
Hi,

On Mon, Dec 16, 2024 at 02:48:44AM -0500, Jeffrey Walton wrote:
> On Mon, Dec 16, 2024 at 2:42 AM 🦓 <czyborra@gmail.com> wrote:
> > YubiKeys is a password manager in a dongle, thus the exact opposite of passwordless.  Your dogs and your goats are passwordless, they reliably serve you but have a built in immune system with redundancies protecting them from abuses of their passwordlessness.
> 
> You don't understand YubiKeys

I applaud your attempt to explain to a zebra on the Internet why
goat-based security may not be suitable for banking and other
similar applications, no matter their "built in immune system".

However, I am concerned that this particular raving lunatic may not be
receptive to the reality-based community and its ways.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

[toc] | [prev] | [next] | [standalone]


#275758

From🦓 <czyborra@gmail.com>
Date2024-12-16 09:10 +0100
Message-ID<JUekV-huGF-1@gated-at.bofh.it>
In reply to#275757

[Multipart message — attachments visible in raw view] — view raw

apt install myownbank

Op ma 16 dec 2024 om 08:57 schreef Andy Smith <andy@strugglers.net>:

> Hi,
>
> On Mon, Dec 16, 2024 at 02:48:44AM -0500, Jeffrey Walton wrote:
> > On Mon, Dec 16, 2024 at 2:42 AM 🦓 <czyborra@gmail.com> wrote:
> > > YubiKeys is a password manager in a dongle, thus the exact opposite of
> passwordless.  Your dogs and your goats are passwordless, they reliably
> serve you but have a built in immune system with redundancies protecting
> them from abuses of their passwordlessness.
> >
> > You don't understand YubiKeys
>
> I applaud your attempt to explain to a zebra on the Internet why
> goat-based security may not be suitable for banking and other
> similar applications, no matter their "built in immune system".
>
> However, I am concerned that this particular raving lunatic may not be
> receptive to the reality-based community and its ways.
>
> Thanks,
> Andy
>
> --
> https://bitfolk.com/ -- No-nonsense VPS hosting
>
>

-- 
+491601449986@linktr.ee/czyborra🦓

[toc] | [prev] | [next] | [standalone]


#275759

From🦓 <czyborra@gmail.com>
Date2024-12-16 09:10 +0100
Message-ID<JUekV-huGF-3@gated-at.bofh.it>
In reply to#275756

[Multipart message — attachments visible in raw view] — view raw

You donot understand your own mistrust.  You are trying to make it
unnecessarily difficult to use your tool.  How would you like a spoon that
phishing-resistently refuses to spoonfeed you unless you have sufficiently
identified yourself as an authority-authorized credit card owner?

Op ma 16 dec 2024 om 08:49 schreef Jeffrey Walton <noloader@gmail.com>:

> On Mon, Dec 16, 2024 at 2:42 AM 🦓 <czyborra@gmail.com> wrote:
> >
> > YubiKeys is a password manager in a dongle, thus the exact opposite of
> passwordless.  Your dogs and your goats are passwordless, they reliably
> serve you but have a built in immune system with redundancies protecting
> them from abuses of their passwordlessness.
>
> You don't understand YubiKeys, their capabilities, and Universal
> Second Factor. The security requirements of U2F are a token that has:
>
>     1. high entropy
>     2. replay resistant
>     3. phishing resistant
>
> Passwords may satisfy (1), but they completely fail at (2) and (3).
>
> And your original problem statement stated memorization was the
> problem you were trying to solve. Even if a YubiKey serves up a fixed
> password (which it does not), then it solves your memorization
> problem.
>
> I have no idea what dogs and goats have to do with things.
>
> Jeff
>
> > Op zo 15 dec 2024 om 15:35 schreef Jeffrey Walton <noloader@gmail.com>:
> >>
> >> On Sun, Dec 15, 2024 at 6:47 AM 🦓 <czyborra@gmail.com> wrote:
> >> >
> >> > my mother is currently struggling to memorize all of my dead
> stepfather's identities and passwords and that makes me wonder how would
> you like an internet of hosts who store everything undeletably and
> barrierlessly readably with no secrets whatsoever to humanity nor any other
> natural or artificial or divine intelligence?   i know this sounds like a
> question for debian-devel or debian-policy but i m dumping it onto
> debian-user as as of now i m not subscribed to any other.
> >>
> >> For some of the larger sites you can use a YubiKey. YubiKeys use the
> >> FIDO/FIDO2 protocols. I believe WebAuthn also supports YubiKeys.
> >>
> >> But I found a lot of sites do not support FIDO/FIDO2 protocols. For
> >> example, most banks and my mother's credit union do not support them.
> >> In this case, I send a letter to the company's legal department and
> >> put them on notice. (I also point out the problems with their current
> >> authentication system).
> >>
> >> If you start switching to YubiKeys, then be sure to use two of them.
> >> The second is a backup YubiKey, and it also gets enrolled when you
> >> convert the account. The backup YubiKey is used in case the first
> >> YubiKey is lost.
>


-- 
+491601449986@linktr.ee/czyborra🦓

[toc] | [prev] | [next] | [standalone]


#275760

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-16 09:10 +0100
Message-ID<JUekV-huGF-5@gated-at.bofh.it>
In reply to#275759
On Mon, Dec 16, 2024 at 2:59 AM 🦓 <czyborra@gmail.com> wrote:
>
> You donot understand your own mistrust.  You are trying to make it unnecessarily difficult to use your tool.  How would you like a spoon that phishing-resistently refuses to spoonfeed you unless you have sufficiently identified yourself as an authority-authorized credit card owner?

Whatever... *Plonk*

> Op ma 16 dec 2024 om 08:49 schreef Jeffrey Walton <noloader@gmail.com>:
>>
>> On Mon, Dec 16, 2024 at 2:42 AM 🦓 <czyborra@gmail.com> wrote:
>> >
>> > YubiKeys is a password manager in a dongle, thus the exact opposite of passwordless.  Your dogs and your goats are passwordless, they reliably serve you but have a built in immune system with redundancies protecting them from abuses of their passwordlessness.
>>
>> You don't understand YubiKeys, their capabilities, and Universal
>> Second Factor. The security requirements of U2F are a token that has:
>>
>>     1. high entropy
>>     2. replay resistant
>>     3. phishing resistant
>>
>> Passwords may satisfy (1), but they completely fail at (2) and (3).
>>
>> And your original problem statement stated memorization was the
>> problem you were trying to solve. Even if a YubiKey serves up a fixed
>> password (which it does not), then it solves your memorization
>> problem.
>>
>> I have no idea what dogs and goats have to do with things.
>>
>> Jeff
>>
>> > Op zo 15 dec 2024 om 15:35 schreef Jeffrey Walton <noloader@gmail.com>:
>> >>
>> >> On Sun, Dec 15, 2024 at 6:47 AM 🦓 <czyborra@gmail.com> wrote:
>> >> >
>> >> > my mother is currently struggling to memorize all of my dead stepfather's identities and passwords and that makes me wonder how would you like an internet of hosts who store everything undeletably and barrierlessly readably with no secrets whatsoever to humanity nor any other natural or artificial or divine intelligence?   i know this sounds like a question for debian-devel or debian-policy but i m dumping it onto debian-user as as of now i m not subscribed to any other.
>> >>
>> >> For some of the larger sites you can use a YubiKey. YubiKeys use the
>> >> FIDO/FIDO2 protocols. I believe WebAuthn also supports YubiKeys.
>> >>
>> >> But I found a lot of sites do not support FIDO/FIDO2 protocols. For
>> >> example, most banks and my mother's credit union do not support them.
>> >> In this case, I send a letter to the company's legal department and
>> >> put them on notice. (I also point out the problems with their current
>> >> authentication system).
>> >>
>> >> If you start switching to YubiKeys, then be sure to use two of them.
>> >> The second is a backup YubiKey, and it also gets enrolled when you
>> >> convert the account. The backup YubiKey is used in case the first
>> >> YubiKey is lost.

[toc] | [prev] | [next] | [standalone]


#275761

From🦓 <czyborra@gmail.com>
Date2024-12-16 09:20 +0100
Message-ID<JUeuB-huLj-1@gated-at.bofh.it>
In reply to#275755

[Multipart message — attachments visible in raw view] — view raw

Op ma 16 dec 2024 om 08:42 schreef 🦓 <czyborra@gmail.com>:

> YubiKeys is a password manager in a dongle, thus the exact opposite of
> passwordless.
>

i ought to reword password to sustain my credibility, any
publickeysignatures (PKS) are of course more unreplayable than
presharedkeys (PSK) but call them token lengths rather than password
lengths they are longer than zeroconf easy zero.  as long as my system are
not immune to an rm -rf / i will not null my own passwords but one day i
will.

[toc] | [prev] | [standalone]


Page 4 of 4 — ← Prev page 1 2 3 [4]

Back to top | Article view | linux.debian.user


csiph-web