189

“Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced on Monday.

(page 2) 50 comments
sorted by: hot top controversial new old
[-] msage@programming.dev 5 points 2 months ago

I'm lost on this - is this better than GPG?

[-] Spotlight7573@lemmy.world 6 points 2 months ago

More usable for the average user and more supported by actual sites and services, so yes.

[-] msage@programming.dev 1 points 2 months ago

Does this require any 3rd party to work? I remember reading a blog, something about attesting the client, which was some big corpo like Google/Apple/Microsoft... that's not for this, right?

[-] Spotlight7573@lemmy.world 2 points 2 months ago

While the defaults are typically to use what the browser or OS has for storage and sync of the passkeys, you can use other things.

Like KeePassXC:

https://keepassxc.org/blog/2024-03-10-2.7.7-released/

As for attestation to how the key is stored securely (like in a hardware key), Apple's implementation doesn't support it for iCloud ones, so any site that tries to require it wouldn't work for millions of people. That pretty much kills it except for managed environments (such as when a company provides a hardware key and wants to make sure that's the only thing that's used).

[-] asdfasdfasdf@lemmy.world 5 points 2 months ago

Meanwhile mobile Firefox doesn't even support YubiKey / FIDO2 for some godforsaken reason.

[-] Pyflixia@kbin.melroy.org 4 points 2 months ago

Whenever I read stuff like this, my mind goes a bit hazy. Because I'm just finding myself asking 'Why and when did the simple mechanic of passwords get this difficult?'

Maybe if password requirements weren't stingingly stupid, companies cared more about actual security and not an obstacle course they've gotta send people through to do one thing. We wouldn't ever know or need to know systems like this.

[-] EncryptKeeper@lemmy.world 2 points 2 months ago

Passkeys are much simpler to use than passwords, password managers, 2FA etc. if simplicity is your goal, Passkeys are your personal wet dream.

load more comments (2 replies)
load more comments (1 replies)
[-] dantheclamman@lemmy.world 3 points 2 months ago

They are really satisfying when they work. I have been impressed by how well they work cross platform in the new bitwarden. It even worked from Android one time with a key made on windows! However, I dread when my mom tells me she needs help with an account and I can't do anything because the key is on her iOS Keychain I don't have access to

[-] Knock_Knock_Lemmy_In@lemmy.world 2 points 2 months ago

What is the difference between a crypto wallet and a passkey?

Is it just that a passkey has less functionality (and therfore better usability)?

load more comments (4 replies)
load more comments
view more: ‹ prev next ›
this post was submitted on 15 Oct 2024
189 points (92.0% liked)

Technology

59983 readers
2296 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS