this post was submitted on 09 Apr 2024
503 points (92.7% liked)

Technology

59374 readers
7248 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 
  • Big Tech has implemented passkeys in a way that locks users into their platforms rather than providing universal security
  • Passkeys were developed to replace passwords for better account security, but their rollout by Apple and Google has limited their potential
  • Proton Pass offers passkeys that are universal, easy to use, and available to everyone for improved online security and privacy.
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 54 points 7 months ago* (last edited 7 months ago) (22 children)

Better yet: use a hardware 2FA token that supports passkeys

[–] [email protected] 36 points 7 months ago (20 children)

The issue is that most of them are limited in the amount of passkeys they can manage.

In the case of the Yubikey 5

Currently, YubiKeys can store a maximum of 25 passkeys.

https://www.yubico.com/blog/a-yubico-faq-about-passkeys/

[–] [email protected] 2 points 7 months ago (14 children)

How is 25 bad? Do you need a passkey for each service /app/website? Can't you use the same key for many services? (trying to understand how they work)

[–] [email protected] 3 points 7 months ago

You only need one per website if you want it to autofill the username, because resident keys held on the security token can be recognized and suggested automatically but otherwise you must first enter your username on the website and let the website send its challenge value for the corresponding domain and account pair so that your security token can respond correctly.

load more comments (13 replies)
load more comments (18 replies)
load more comments (19 replies)