4 ms·
Name one system that accepts passkeys and allows you to setup two of them. as is the recommended best practice everywhere. even OTP tokens generators goes to g
by 007asdflkjsfd 3y ago
Name one system that accepts passkeys and allows you to setup two of them. as is the recommended best practice everywhere.
even OTP tokens generators goes to great lengths to give a false sense o security that their seed is unique simply by hiding it from the user UI. Google authenticator will happily save the seed and seed tokens in their cloud and allow you to restore. all while still hiding it from the user.
if you have twenty accounts on your OTP, and get a new phone, you have to log in on each site/product. Disable and re-enable 2fa. That's some 2~5min each.
back to passkeys... do you think this will last when google is getting tons of spam on gmail because microsoft is not careful on their spam bot protection? likely google will just shutdown the integration and demand you use google or apple for gmail. This will happen all over all the time.
- dvzk 3y agoLike 99% of people in this thread, you are conflating distributed non-device-bound credentials (passkeys) with hardware security keys.
- donmcronald 3y ago> distributed non-device-bound credentials If they can be distributed they can be stolen, right? I don't see how it's any better than a password manager at that point.
- dvzk 3y agoYes. Depending on the threat model, it may or may not be better. Many organizations won't be allowing remote passkey sign-in for employees. For people at home, the elimination of passwords will reduce rates of phishing and credential-stuffing attacks.