4 ms·
Yeah, well what I want is a (physical, literal) membership card like I have at the gym or library. I think "regular" people can learn to use USB tokens, and tha
by rad88 4y ago
Yeah, well what I want is a (physical, literal) membership card like I have at the gym or library. I think "regular" people can learn to use USB tokens, and that they might make more intuitive sense than passwords. These places don't challenge me for the "secret password" when I come in, I just present or scan my card.
It's very tricky obviously, in terms of engineering and operations, for an internet based company to arrange anything similar. But I don't think it's too mentally foreign for the user (assuming we develop good standards).
So cards make sense to me. Way more sense than passwords. Maybe someone else feels more comfortable with the details living inside their phone, but that doesn't affect my mental model. Users don't need to understand or be taught the entire standard.
- tialaramex 4y agoAs you will have seen in lots of other posts to this topic, people want privacy and "I just show my membership ID everywhere, what's the problem?" unsurprisingly is not what they had in mind. So, FIDO preserves privacy by minting unique credentials for each site where you use it. This is invisible to the user of course, for them it's just the case that you use your FIDO authenticator everywhere (that it works) and now it's secure.
- rad88 4y agoI understand that. I was responding to the idea that hardware tokens like yubikey, in fact all alternatives to passwords, are too complicated for regular people to understand. And also saying that multiple options, to accommodate different people/scenarios, are fine and don't have to be complicated from the user's perspective. By way of analogy (admittedly I didn't make that very clear).