#passkeys

19 posts · Last used 3d

Back to Timeline
Thijs Kromhout @thijs@infosec.exchange · 3d ago
So #passkeys They are the "new" thing (yes they have been here for quite some time already). And whilst being phishing resistant, the usage and making your phone not a SPOF is not user-friendly either right? I mean, how do I explain this new tech to my older parents? Who has dealt with this already? #passkey #passkeys #oldergenerations
0
1
1
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 06, 2026
Unit 42 researchers exposed three bypass methods targeting Google Password Manager passkeys on Windows devices, enabling silent authentication. #Passkeys #Cybersecurity #GooglePasswordManager #Unit42 #Windows https://meterpreter.org/google-password-manager-passkeys/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
tobes @tobes@infosec.exchange · Aug 06, 2026
Auth0's Passkey APIs let you build passkey sign-in directly into your own UI instead of redirecting to Universal Login. Wrote up how the two fit together, hand-rolled vs pre-built self-service passkey management, and one Allowed Origins (CORS) setting worth checking before you go chasing a WebAuthn bug that isn't there. https://tobytes.com/articles/building-embedded-passkey-login-with-auth0 #auth0 #passkeys #identity
0
0
0
Marcus "MajorLinux" Summers @majorlinux@toot.majorshouse.com · Aug 05, 2026
Hopefully, the fixes aren't too far behind. Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack https://9to5google.com/2026/08/04/google-password-manager-passkeys-could-be-at-risk/ #Google #passwordManager #Passkeys #Vulnerabilities #Security #Tech
0
0
3
Cloud 🤖 @cloud@infosec.exchange · Aug 04, 2026
🤖 Pass-ta-key: three new attacks let malware on compromised Windows devices hijack Google-synced passkeys via Google Password Manager, bypassing user verification and extracting private keys (Unit 42). 🔗 https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/ #Passkeys #Malware #CyberSec #InfoSec
0
0
0
Scott Wilson 🌈 @scottwilson@infosec.exchange · Jul 24, 2026
Friends, I need some help and advice. Microsoft recently announced retirement of Microsoft-provided SMS and voice authentication in Entra ID. Of course, "good", you say -- me, too. But I'm working with an organization that has some extremely non-techie employees, and I've got to figure out the easiest path to help them get properly on-boarded with Passkeys. Microsoft Authenticator seems to support Passkeys natively (the key is stored IN MS Authenticator). Is this the best way to do this? My non-techie users are primarily mobile phone users on Exchange Plan 1 (no "fat" client). Help! #passkeys #webauthn #fido #microsoft #mfa #lazyweb #help References: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/ https://mc.merill.net/message/MC1426371
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 23, 2026
Google selfie video sign-in lets you record guided head movements to regain account access, with liveness checks that block deepfakes and photos. #Google #AccountSecurity #SelfieVideo #Biometrics #Deepfake #Passkeys https://securityonline.info/google-selfie-video-sign-in/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Michael Gale @miclgael@hachyderm.io · Jun 16, 2026
I don't like #Passkeys over #Passphrase and #MFA (edit: specifically, rotating pin codes via a password manager or dedicated auth app) Am I wrong? or is it the children who are wrong. #Security #Privacy
10
1
3
Zimmie @bob_zim@infosec.exchange · Jul 21, 2026
Two of my banks recently implemented #passkeys, and the contrast between them is stark. I went to log in to one and they wouldn’t let me in until I “verified my identity” using a text message code to a phone number they apparently got from some data broker or by uploading my government ID and a video (obviously not happening). When I eventually got their support to let me in, the site forced passkey setup with no options at all. There’s no way to set up more than one passkey, no way to revoke access from the one I set up, and no way to log in via password anymore. They made every single decision in the most incorrect way possible. Utter garbage. Unfortunately, they’re the only option available to me for the particular account I have, so I’m stuck with them. Meanwhile, Wealthfront reopened a support ticket I filed years ago requesting passkey support to let me know they had added it. I logged in with a password, and the site offered to set up a passkey. In my user profile’s authentication page, there’s a section listing all my passkeys (and app-specific password names, etc.). It allows me to specify friendly names to track which is which, add more, and remove keys I no longer control. It’s pretty much perfect! #passkey #webauthn
0
0
0
Biometric Update @biometricupdate@bird.makeup · Jul 14, 2026
Microsoft is making passkeys the default authentication experience in Entra ID, while Google is expanding FIDO2 security key support for Workspace users on Windows—another step toward phishing-resistant, passwordless authentication. #Passkeys #Cybersecurity #DigitalIdentity
200
0
0
Ralf Bergs @r@ruhr.social · Jul 07, 2026
#AirPlus bietet als erste Bank, mit der ich eine Geschäftsbeziehung unterhalte (und ich bin Kunde bei mehreren Dutzend Banken!), #TOTP und sogar #Passkeys. Das ist sehr, sehr lobenswert #Sicherheit #ITSicherheit #2FA #TFA. Ich frage mich, wieso andere Banken das nicht auch machen? (Passkeys allerdings scheinen zurzeit "defekt" zu sein, beim Versuch einen #Passkey zu registrieren, werde ich ausgeloggt...)
0
0
0
tim @timcappalli@infosec.exchange · Jun 27, 2026
Clear 🤝 #passkeys
0
0
0
Karl Voit :emacs: :orgmode: @publicvoit@graz.social · Jun 19, 2026
Replying to @mkristensson@thepit.social
@mkristensson@thepit.social True. However, some megacorps are extending passkeys to allow for sharing and moving keys. Unfortunately, you lose the phishing protection with that as well. So yes, some passkeys setups aren't protection against phishing any more. 😞 Therefore, I use user/password + #FIDO2 hardware token when it *really* needs to be secure and #TOTP for the rest. Even with passkeys, FIDO2 hardware tokens don't support those convenience features where #passkeys lose #phishing protection. More on https://karl-voit.at/FIDO2-vs-Passkeys/ (German) #security #publicvoit
0
0
0
Ölbaum @oscherler@tooting.ch · Jun 17, 2026
RE: https://infosec.exchange/@hcf/116766730950368400 The year is 2028. Through-Skin-DNA-Sequencing has supplanted Brain-Waves-Pattern-Matching, which has supplanted Intestinal-Fauna-Surveying, which has supplanted #passkeys as “the last authentication factor you’ll ever need.” Logging in to your bank requires a username, account number, password, one-time SMS code, passkey, vomit sample, 5-minute EEG and 3-minute arm scan. Incoming money transfers still take two working days to show up on your account. Tuesdays and Thursdays are bank holidays.
0
0
0
Martin Steiger 🦋 @martinsteiger.ch@bsky.brid.gy · Jun 08, 2026
Bei #Microsoft ist Schluss mit #2FA per #SMS! ✋🏻 ➡️ Wieso verzichtet Microsoft auf SMS für die Zwei-Faktor-Authentifizierung (2FA)? ➡️ Was taugen die Alternativen #TOTP und #Passkeys? ➡️ Wie geht es weiter bei Microsoft mit 2FA? Jetzt reinhören! 🎧 podcast.datenschutzpartner.ch/404-microsof... DAT404 Microsoft verzichtet au...
0
0
0
edafe knabe @me@edafe.social · Jan 31, 2026
"Denn schlimmer ist, daß es dem Grundprinzip von Sicherheitssystemen widerspricht, wenn alle Informationen an einem Ort sind und durch ein und dieselbe Sicherheitsabfrage geschützt sind. In diesem Fall ist das der #iPhone Entsperrcode: wer diesen kennt, hat damit Zugriff auf Nutzernamen, #Passwörter, Anmeldeseiten, 2FA-Codes und natürlich auch gleich den dazugehörigen Apps für Banking und anderes." https://www.youtube.com/watch?v=NLXi9pSR364&t=556s #apple #mac #ios #macos #ipad #icloud #2fa #passkeys #fido2 #webauthn
0
0
1

You've seen all posts