this post was submitted on 15 Oct 2024
189 points (92.0% liked)

Technology

60033 readers
2683 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
 

“Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced on Monday.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 2 months ago (3 children)

Whenever I read stuff like this, my mind goes a bit hazy. Because I'm just finding myself asking 'Why and when did the simple mechanic of passwords get this difficult?'

Maybe if password requirements weren't stingingly stupid, companies cared more about actual security and not an obstacle course they've gotta send people through to do one thing. We wouldn't ever know or need to know systems like this.

[–] [email protected] 11 points 2 months ago

With passkeys you never need to worry about the storage method used by the site. Some sites STILL store passwords in plaintext. When that database gets hacked, it’s game over.

A public passkey, even stored in plaintext, is useless to an attacker.

Maybe that doesn’t matter for you or me, with our 64-character randomly generated passwords unique to each service, but the bigger picture is that most people just use the same password everywhere. This is how identity theft happens.

[–] [email protected] 5 points 2 months ago

'Why and when did the simple mechanic of passwords get this difficult?'

When and because people started storing all their intimate personal details on the internet and hackers sought to exploit those details.

Maybe if password requirements weren't stingingly stupid, companies cared more about actual security and not an obstacle course they've gotta send people through to do one thing.

The obstacle course is the security, unfortunately. That's the problem this aims to solve.

[–] [email protected] 2 points 2 months ago (1 children)

Passkeys are much simpler to use than passwords, password managers, 2FA etc. if simplicity is your goal, Passkeys are your personal wet dream.

[–] [email protected] 1 points 2 months ago* (last edited 2 months ago) (1 children)

That one site - what was it, Mozilla's/Gnome's git? - that needed Aegis for login. Which is unlocked by pasword btw.

[–] [email protected] 1 points 2 months ago

Was this reply meant for me? I’m not sure what you’re saying