Passkeys: A Shattered Dream (fy.blackhats.net.au)
from thomask@lemmy.sdf.org to cybersecurity@sh.itjust.works on 26 Apr 11:17
https://lemmy.sdf.org/post/15869322

#cybersecurity

threaded - newest

Illogicalbit@lemmy.world on 26 Apr 12:14 next collapse

A good read and a validation that it’s frequently a good idea to approach new security technologies with caution. The new hotness isn’t always the best thing.

sugar_in_your_tea@sh.itjust.works on 26 Apr 14:07 collapse

Honestly, when I saw “passkeys,” my first thought was “vendor lockin.” Google and GitHub did it with SSO using OAuth, and they’re doing it again with passkeys.

Honestly, this is a “surprised Pikachu” moment for me. The closer you get to convenience, the more the big players will want to lock you in:

  • biometrics
  • voice recognition
  • passkeys

Passwords are hard to lock down because it’s easy to switch to something else.

4grams@awful.systems on 26 Apr 14:25 collapse

I love the promise of passkeys but it’s been painfully obvious the promises are just wallpaper over the actual intent which is vendor lockin.