Post #2359376
2026-05-10 19:16 UTC
Replies (3)
-
@luana@wetdry.world 2026-05-10 19:18
@rmondello@hachyderm.io wait, you can’t? Wtf lmao
-
@ErikvanStraten@todon.nl 2026-05-10 19:52
@rmondello@hachyderm.io : what makes passkeys strong: 1. Software checks the domain name, which makes phishing hard; 2. Https is enforced, which helps prevent AitM attacks (unless Cloudflare et al. come into play); 3. A unique, long, unguessible, randomly generated "password" (public key) per account: dumb password rules and broken human RNG's no longer apply. The rest is marketing (including the -hyped- asymmetric cryptography). The "advantage" of denying the owner access to their own private keys hardly makes sense as long as session cookies are not device-bound. The disadvantage of not being able to back up ones own private keys is the risk of vendor lock-in and the underestimated huge risk of account lockout [1]. And the latter leads to the necessity of being able to log in using weak authentication after the user loses access to their private keys. @brandonbutler@mastodon.social [1] https://seclists.org/fulldisclosure/2024/Feb/15 #Passkeys #Phishing #PhishingResistant #AsymmetricCryptography #AndroidPasskeys #androidPasskeysGone #iOSpasskeys #iPadOSpasskeys #ApplePasskeys #BackUp #Export #BackUpPasskeys #ExportPassKeys #PasskeyBackUps #PasskeyExports
-
@kylebshr@mastodon.social 2026-05-10 20:23
@rmondello@hachyderm.io @brandonbutler@mastodon.social the only thing on my wwdc wishlist