• Katana314@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    ·
    5 days ago

    Sites keep pushing Passkeys on me. I tried them. Did not work cross device. Did not integrate with every app. For now, I gave up on them.

    It’s only a secure technology when it works and the key turns in the lock.

      • AmyAye@nord.pub
        link
        fedilink
        English
        arrow-up
        8
        ·
        5 days ago

        Got I wanted a Yubikey for so long hearing about them. And earlier this year, Work got everyone Yubikeys for work, and they are essentially mandatory to use, and good fucking God so I hate Yubikeys.

        Now I have this thing I have to carry around and dig out and plug in and my phone is going to eventually require it too and what the fuck happens when I inevitably lose it or it gets broken because it’s very flimsy feeling and already looks a little bent.

          • AmyAye@nord.pub
            link
            fedilink
            English
            arrow-up
            2
            ·
            4 days ago

            I actually keep commenting that “I wish I could order more of these” especially because, as far as I can tell from what numbers I have seen, we paid almost nothing for these. I wanted to bulk order a dozen at the price they paid (if it’s accurate) and it would cost me less than one from Amazon.

      • Katana314@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        This effort was using a third-party cross-platform password manager.

        The specific case was a mobile game that needed to open a web browser that logged into a secondary account system, which I had set up to use passkeys. The in-app browser didn’t seem aware of my phone’s password manager plugin, and so it allowed no way to get in. Other times, logging in on a web browser with the password manager fully working simply gave an error - which could be blamed on the individual account provider, but then if I’m taking a chance on each passkey account, it’s again pointless.

        • otacon239@lemmy.world
          link
          fedilink
          English
          arrow-up
          9
          arrow-down
          1
          ·
          5 days ago

          Common misconception. The whole point of a password manager is so that you can have a unique password for every account. This means that of one site is compromised, only that one site is lost.

          Passkeys take this a step further by taking a keylogger out of the equation since you’re no longer typing the password. And by using biometrics instead of a password to unlock your password manager, no password is ever typed significantly reducing the ability to steal it. Even better if it asks for both.

          And to the point of one point of failure, this is always the case as you could get knocked on the head and forget all your passwords. You now only have to manage one potential point of security failure rather than however many accounts you have online.

          • AmyAye@nord.pub
            link
            fedilink
            English
            arrow-up
            3
            ·
            5 days ago

            Yubikey isn’t really biometrics though is it? You can like it with any body part or even a hot dog if you wanted.

            • otacon239@lemmy.world
              link
              fedilink
              English
              arrow-up
              8
              arrow-down
              1
              ·
              5 days ago

              At the end of the day, if someone is targeting you, specifically, they WILL succeed. See the Wrench Method. The point is making yourself a more difficult target for the blanket hits and data leaks.

    • FiniteBanjo@feddit.online
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      5 days ago

      Yeah I don’t like those things. If your password is two or three words, with a special character and 3 numbers anywhere before between or after, it would take millions of years to brute force, and then you’re still covered with auth codes 2 factor. Theres no point in having a password so complex that you yourself can’t remember it.

      The only exception is when a common password is found in a data breach, but you should have unique passwords for work and financial accounts and theres no guarantee that the password managers won’t be hacked at some point.