icing,
@icing@chaos.social avatar

I do not trust passkeys, because I seem no longer to be the one controlling the access.

Instead google or apple are.

Sure, they ask me for my face or thumb, but my brain is no longer a vital part of the process.

I can understand that companies might prefer that. The medium failure rate will be much better the more employees you have.

But for me as an individual the failure impact seems catastrophic, or at least unclear how to mitigate.

ljrk,
@ljrk@todon.eu avatar

@icing So you also do not use ssh keys but password auth?

icing,
@icing@chaos.social avatar

@ljrk I use password protected ssh keys and ssh-add.

ljrk,
@ljrk@todon.eu avatar

@icing So you use an SSH key manager and your login is not performed by "your brain" but ssh-agent (which had lots of quite bad CVEs btw, but that's just a side note).

Yet, you don't like using those keys for Web by claiming (quite arbitrarily and falsely) that Google or Apple are controlling the keys. Kinda, as if you would use iCloud as your SSH storage with a proprietary Apple ssh-agent.

maxheadroom,
@maxheadroom@hub.uckermark.social avatar

@icing but that's not a Passkey problem but your choice of the Passkey store. You could store the passkey in a different tool that you'd unlock by other means. Or even use a hardware token. Right?

mxk,
@mxk@hachyderm.io avatar

@maxheadroom @icing yes. You can use every password manager that implements it for passkey. The Usercase for passkeys is people who do not want to deal with enrolling multiple ubikeys to every service they use.
Given that you trust your phone and the passkey applications, you get comparable security to hardware security tokens, while solving the recovery problem.
And make no mistake, recovery is, what makes ubikeys unusable for most people.

icing,
@icing@chaos.social avatar

@mxk @maxheadroom Which password manager do you trust for this? I was once on 1password before they killed local stores. No desire to use cloud storage.

mxk,
@mxk@hachyderm.io avatar

@icing @maxheadroom I don't, but I also fundamentally dislike the idea of using my phone as a root of trust.
But this doesn't change that I think that passkeys are a gigantic improvement for the average user.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • GTA5RPClips
  • magazineikmin
  • InstantRegret
  • everett
  • osvaldo12
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • kavyap
  • Durango
  • ngwrru68w68
  • thenastyranch
  • DreamBathrooms
  • JUstTest
  • khanakhh
  • Leos
  • cisconetworking
  • ethstaker
  • modclub
  • tester
  • cubers
  • tacticalgear
  • provamag3
  • normalnudes
  • anitta
  • megavids
  • lostlight
  • All magazines