you are viewing a single comment's thread
view the rest of the comments
[–] 13 points 3 days ago (9 children)

Way too soon for anything that takes itself seriously to rely on passkeys.

Passkeys are just a mess right now. Despite attempts to improve things, it's gotten even worse over the past few years. The tech giants, password managers, browsers and websites have just not been willing to work well with one another through FIDO. I'm guessing the tech giants are most at fault but who knows.

  • source
  • hideshow 9 child comments
  • [–] 3 points 2 days ago

    I keep saying this myself. I feel bad because there is a real problem they are solving (phishing) but ultimately it is an overly technical solution to an extremely human problem. They're only as strong as their weakest recovery method and the inability for the average user to understand the technical implementation and ramifications takes power away from a personally held secret (problematic as that may be) and shifts it towards more platformization.

    It all just makes me vaguely uncomfortable in ways I have a problem fully articulating.

  • source
  • parent
  • [–] 4 points 3 days ago (3 children)

    I haven't been following what these are or why they're flawed. It looks to me like they're taking Two Factor Auth, and removing one of the factors (the password). Now all you need is a device? If the device is lost or itself compromised, isn't that still a single point of failure?

  • source
  • parent
  • hideshow 3 child comments
  • [–] 6 points 3 days ago (2 children)

    You can backup a 2fa code on so many multiple managers at the same time, how the hell can one backup a pass key?

  • source
  • parent
  • hideshow 2 child comments
  • [–] [S] 1 point 3 days ago (3 children)

    Isn't the main issue moving them and that was effectively solved this week?

  • source
  • parent
  • hideshow 3 child comments