this post was submitted on 14 Feb 2024
263 points (88.8% liked)

Technology

59374 readers
7261 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Passkeys: how do they work? No, like, seriously. It’s clear that the industry is increasingly betting on passkeys as a replacement for passwords, a way to use the internet that is both more secure and more user-friendly. But for all that upside, it’s not always clear how we, the normal human users, are supposed to use passkeys. You’re telling me it’s just a thing... that lives on my phone? What if I lose my phone? What if you steal my phone?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 4 points 9 months ago (2 children)

Only if you're specifically targeted. I know enough regex to know that nobody is going to bother trying to parse known passwords to identify patterns like that when there's a billion suckers who use 'password123' for their bank accounts.

As long as the pattern is not super predictable, and aren't dictionary words, nobody is brute forcing that.

[–] [email protected] 3 points 9 months ago

Even a minute mental load at everything you need to log into in a day is still more than the zero mental load I have when using a password manager.

It’s not just more secure, it’s far more convenient. Plus once you start to share a life with someone, you can share all your accounts and passwords effortlessly as well.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago)

These would be extremely easy to detect with regex. Just look for the service name in a password, including common leet speak conversion.

Password123-Facebook then easily becomes Password123-GitHub or Password123-Walgreens.

I can assure you, if I was a bad actor that got my hands on a password dump, I’m checking for these kinds of passwords pretty early on.

Edit: A word.