• Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    1
    ·
    2 days ago

    I really wish that SQRL had taken off, as it solved most of the problems noted. It was effectively passkeys that you generated on the fly based on your private key (which you can back up and restore to other platforms if necessary) and the website domain by scanning a QR code (or clicking rh QR code if your on the same device) and sends the signed challenge to the website to auth you.

    No need to login to your manager on random systems, no issues with platform lock-in, no worries about dedicated hardware, no worry about losing your access if your device dies (assuming you backup your shit).

    • oppy1984@lemdro.id
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      Steve put so much time into it too. SQRL really is the superior method of the two.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          If SQRL was adopted, then the popular manifestations would have just as much vendor lockin, with built in password managers hosting the master private key without export option.

          Passkey is not inherently vendor lock in. It’s mostly a consequence of password managers doing software passkeys and not making it reasonable to export private keys. It does have a mechanism a site can use to lock to “trusted vendors”, but if a site does that, that is on them for being dickish.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          Passkeys cross vendor sync is in the works right now and you can already self host with Bitwarden

      • WhyJiffie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        it does not depend on the name. like, we all use Transmission Control Protocol and HyperText Transport Protocol, and nobody cares because they don’t need to know. things can also be renamed before starting use in production, like we aren’t normally calling tech by their RFC numbers