4 ms·
> so long as that remains an option. This will remain an option. Probably forever. The reason is simple; comfort is a selling point. And everything requires mo
by usrbinbash 5y ago
> so long as that remains an option.
This will remain an option. Probably forever. The reason is simple; comfort is a selling point. And everything requires more energy to set up than chosing a plain old password. Sure, security is a selling point as well, but its really hard to argue that to consumers, when security comes at a comfort-cost.
So in my opinion, if, passwords are here to stay anyway, we should explore avenues to, on average, make them stronger and get people to use unique ones for their services with as litte impact to comfort as possible. Password managers are a very good step in that direction.
- Ajedi32 5y ago> And everything requires more energy to set up than choosing a plain old password That's only true so long as there's no mainstream alternative. If everyone needs to have WebAuthn set up anyway for some other service they're using that doesn't use passwords, then the marginal "comfort-cost" of adding another account to system will be even lower than the cost of signing up with a password. (Choose a password? Or just click the "use WebAuthn" button?)
- usrbinbash 5y ago> If everyone needs to have WebAuthn set up anyway for some other service they're using that doesn't use passwords That service will have to explain to its customers why they need to get/install/configure a WebAuthn Authenticator (which includes taking care of another device / another piece of software), when their direct competitors allow users to log in with just a plain old password. Said explanation doesn't just have to convince the average customer used to passwords, it also has to convince people like me, who use password credentials in a highly secure and reliable way. They will also have to explain why if, eg. the USB connector gets damaged (in the case of a hw-authenticator) because it has been stored in the users pockets with a bunch of keys and thigh-sweat, they suddenly can't access their emails any more. WebAuthn has been around for almost 8 years now (published May 2016). Big Players enthusiastically support it. And still all major services allow login via password credentials.
- Ajedi32 5y agoWebAuthn does not require a USB device. For the first few sites that deprecate passwords the explanation will be something like "we have strict security requirements, passwords are not secure, we're getting rid of them". Once that becomes the norm for high-security applications other sites will follow, since they won't have to deal with the initial barrier of getting users to set up WebAuthn. > WebAuthn has been around for almost 8 years now (published May 2016). Big Players enthusiastically support it. They enthusiastically support it for 2FA. I haven't seen any concerted effort yet to use WebAuthn as a password replacement, or to implement any of the basic features that would make that viable (like synced credentials). I find that very disappointing, as we could have been well on our way to phasing out passwords already if the big players in the space had started this 4 years ago back when the WebAuthn spec was finalized.