5 ms·
The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key. The solution is to se
by metafunctor 3y ago
The point is that the private key resides on a tamperproof piece of hardware. Malware, viruses, or shoulder surfers cannot copy the key.
The solution is to set up multiple pieces of secure hardware, not writing down the keys to the castle on a piece of paper.
- kahnclusions 3y agoGreat so now people need to be rich enough to own multiple phones? Really. The solution can’t be “buy multiple devices” when the average person can barely afford to maintain one working device.
- Dlanv 3y agoYour computer can also be a passkey. I currently use both my laptop and my computer as a passkey, and a USB drive. So I have 3 backups to my Google account. It is true that you do need to be rich enough to own a phone and ~100 USD of something else (laptop or USB), which does put redundancy out of the reach of a large portion of the world. But then they can just use regular 2fa at the expense of not being phishing-proof.
- tmpX7dMeXU 3y agoYou have to be within several layers of bubbles to not see how small a percent of the general population are going to even understand any of this BS. Things being this complicated makes them a non-starter. A nerd vanity project. And this isn’t a knock on the “intelligence” of the general population. They quite rightfully won’t want to spend their limited time on God’s earth learning about all this.
- svieira 3y agoYes, but in order to add new items to each piece of hardware you have to be physically co-located with all the pieces of hardware you want to use as your backups. Which means they cannot be geographically distributed (or if they are that there is a period of time in which you aren't fully backed up). Which means you're either in a place where you can loose all your keys (e. g. a house fire or a flood) or your in a place where you can loose all the devices that have a key.
- wetpaws 3y ago[dead]
- brundolf 3y agoIt's still a stronger key than virtually any password would be, and is (to my understanding) resistant to data breaches But information sovereignty is crucial when it comes to this stuff; losing that is a regression that will cause problems
- diogenes4 3y agoI'm much more concerned about my access being tied to physical hardware than I am about "malware".
- MrDrMcCoy 3y agoHow many of those devices do you think people are willing to buy, keep updated, AND store off site? A fire, car accident, flood, or major theft could wipe multiple devices out in one fell swoop. Unless there's a secure way to make passkeys portable and able to be backed up in a secure manner off-site, I will avoid this tech like the plague.