4 ms·
This is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or l
by netsec_burn 3y ago
This is an interesting direction. It's worth noting that biometrics, like fingerprints or facial recognition, aren't really 'secrets'. They can be observed or leveraged without a users knowledge or consent, and in many ways function more like a username than a password.
- csjh 3y agoDon't they need both physical access to device + fingerprints/face?
- px43 3y agoYes.
- the_snooze 3y agoPasskeys really aren't biometric authentication per se. If you use TouchID, for instance, Google isn't authenticating you based on your fingerprint. Rather, the fingerprint merely unlocks the cryptographic key pair that's then used to authenticate you. I use Yubico Security Keys myself as passkeys. They're protected by a 6-digit PIN. But that PIN is strictly local to the device, meant to prevent snoops from logging in just by having physical access to the device (the keys get blown away after 10 consecutive unsuccessful PIN attempts). When I enter the PIN, the keys unlock, and it's those keys that get me into my Google account.
- kube-system 3y agoPasswords are also not entirely secret, as they're shared by definition. Passkeys use public-private key crypto, which is more secure in every way.
- mlk 3y agoPassword should be stored as salted hash, so they are not really shared.
- kube-system 3y agoSalted and hashed passwords must be shared but not (hopefully not) stored.