• ranandtoldthat@beehaw.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 days ago

    Way too soon for anything that takes itself seriously to rely on passkeys.

    Passkeys are just a mess right now. Despite attempts to improve things, it’s gotten even worse over the past few years. The tech giants, password managers, browsers and websites have just not been willing to work well with one another through FIDO. I’m guessing the tech giants are most at fault but who knows.

    • audaxdreik@pawb.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      22 hours ago

      I keep saying this myself. I feel bad because there is a real problem they are solving (phishing) but ultimately it is an overly technical solution to an extremely human problem. They’re only as strong as their weakest recovery method and the inability for the average user to understand the technical implementation and ramifications takes power away from a personally held secret (problematic as that may be) and shifts it towards more platformization.

      It all just makes me vaguely uncomfortable in ways I have a problem fully articulating.

    • HarkMahlberg@kbin.earth
      link
      fedilink
      arrow-up
      4
      ·
      2 days ago

      I haven’t been following what these are or why they’re flawed. It looks to me like they’re taking Two Factor Auth, and removing one of the factors (the password). Now all you need is a device? If the device is lost or itself compromised, isn’t that still a single point of failure?

      • jnod4@lemmy.ca
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 days ago

        You can backup a 2fa code on so many multiple managers at the same time, how the hell can one backup a pass key?