Elektrine lite

← Feed

@kevlin@mastodon.social

Post #616185

2026-03-06 09:21 UTC

A lot of security is based on trust. Trust relies on competence. The security theatre I get from a lot of sites and apps, sometimes elaborated through MFA, does not inspire such trust. That device you tell me is unrecognised? It's the one I've used to access the app every day for at least the last year. If you want to convince me your app is secure, start with competence. Poorly engineered products don't do that. KPI-driven product staff don't do that.

Replies (1)

  • @danhugo@fosstodon.org 2026-03-07 08:07

    @kevlin Isn’t there a push toward zero trust security? Also, whatever happened to client side certs? Too cumbersome, I suppose, and I guess there is an argument that passkeys are a light weight take on this, sort of, but… In the age of wacky age verification and voter identification rules and laws, all of this is suddenly super-interesting. Again. As it should be.

    Open ##1261283