5 ms·
Someone correct me if I'm wrong. But, does WebAuthn really improve authentication? With WebAuthn, instead of a secret password, you store a secret key. Why not
by hahnchen 4y ago
Someone correct me if I'm wrong. But, does WebAuthn really improve authentication? With WebAuthn, instead of a secret password, you store a secret key. Why not just use really long passwords behind password managers? You're using some software to save a secret in either case.
- samjmck 4y agoI don’t know if it improves security if you already use a password manager but I guess it will mostly be more accessible and practical
- drexlspivey 4y agoSome malware could steal your keys for example when you have your PM unlocked or snatch it from the clipboard but it’s impossible with hardware keys. It also won’t let you get phished but arguably PMs protect against that too.
- kraftomatic 4y agoI believe it also validates the site via ssl to killnphishing. with passwords you can still trick users.
- PassageNick 4y agoWebAuthn drastically improves authentication. For starters, it doesn't release any secret information into the wild. Instead, it uses a public/private key pair to challenge the user to decrypt something that only she or he can decrypt. The website (as an example) no longer stores anything but your public key, which doesn't reveal anything. Secondly, you can't give away your passkey information so it is for all practical purposes unphishable. (I can't conceive of a way that it might be phished, but that doesn't mean there isn't one.) In addition, it is super-duper easy on users. They don't have to remember anything, and can login with the touch of a finger or a glance at the camera. This is a huge step forward in authentication.