3 ms·
This is an extraordinarily bad take. :) - The biggest threat almost all users face is in the form of remote attackers: password phishing, database leaks + pass
by md_ 3y ago
This is an extraordinarily bad take. :)
- The biggest threat almost all users face is in the form of remote attackers: password phishing, database leaks + password reuse, tricking users into installing malware, etc. Local attackers are so far down the list of concerns that, really, using unique passwords and storing them on Post-Its is, for most people, an improvement in security!
- Leaving a Yubikey in the computer is, in fact, the normal, intended mode of operation--that's why Yubico makes low-profile keys that you can just leave in your USB port. Yes, an attacker can just steal the key, but the key alone is insufficient to authenticate in most uses; almost all relying parties using keys that don't support user verification will also require a password.
- The article was about passkeys, not FIDO security keys. Subtle difference, but, importantly, passwordless authn using passkeys requires the authenticator to support "user verification" mode (like a PIN/screenlock/biometric).
- swiftcoder 3y ago> The biggest threat almost all users face is in the form of remote attackers I'm not sure what users you interact with most on a regular basis, but for a pretty significant portion of the population, the most likely threats to their online (and offline) safety are jealous boyfriends/spouses/parents
- brazzy 3y agoActually a valid point, but if you're gonna be that condescending about someone not considering that part of the population you should have something better than weasel words to argue how big it is.
- ghaff 3y agoYou certainly have to consider your situation. If you live alone or with someone you trust (who you want to have access to your accounts if something happens to you), writing down passwords on paper and sticking that in a drawer or in some book on a bookshelf somewhere is likely pretty reasonable. Maybe have them backed up in an encrypted file in the cloud someplace as well. Live in a house with a bunch of other people out of school? Extended family some of which you don't get along with in and out of the house a lot? Certainly for work stuff in an office. Probably not so much. The risk may not be that great in absolute terms but I'd absolutely think twice.
- swiftcoder 3y ago> if you're gonna be that condescending about someone not considering that part of the population We're talking about somewhere around 65% of the overall population. Entirely ignoring women and children from your target market warrants a little condescention
- xracy 3y agoIt's possible that I'm just missing the distinction here between passkeys and FIDO security keys. Because all of the things I'm seeing in this space fall into just one factor of authentication. I will point out that I explicitly called out 2FA as being necessary. And any of PIN/Biometric (not sure what screenlock is), seems like that 2nd factor to me. So if these are different things, then the rollout is going really rocky (on par with Wii vs. Wii U), and they should probably come up with a better naming schema.
- md_ 3y agoPasskeys (as password replacements) generally require user verification (like a PIN or fingerprint) to unlock the secret. I don't think very many people know what "security keys" or "FIDO" are, to be honest, so you're probably in the tiny part of the Venn diagram of people who a) know what those things are but b) don't know that they support user verification. ;)