3 ms·
None of my relatives care about remembering passwords, not even those more technically inclined. They create the password, and 30 seconds later forget they even
by alin23 3y ago
None of my relatives care about remembering passwords, not even those more technically inclined. They create the password, and 30 seconds later forget they even did such a thing.
Someone even lost access to their iPhone 8 because after replacing the screen, they got a "This device is locked". But they could not remember their iCloud email and password, they didn't need to remember it. The phone worked fine for years without it. Now it's a perfectly functioning phone, but locked and useless.
The difference between "account" and "email" is also lost on them. Not a week goes by before someone needs to access a new site they need to register, and I get the same:
I already have this "gmail" thing, why do I need to create another gmail??
(because they have to use their email as the "username")
And this is the norm! Most devs creating these systems don't understand this.
A passkey sounds marvelous to me, it finally uses the thing that should be the password: the person itself. That is what a password should say after all:
yes, this is me, the person that owns this account
why do I need to tell you this mumbojumbo words and symbols to know that it's me? you have my face and finger data, match them please.
But that's only if it seamlessly supports biometrics like FaceID/TouchID/BrainwavesID-or-something, otherwise it will be just as useless.
- jksflkjl3jk3 3y ago> you have my face and finger data, match them please. No thanks. A kidnapper or the government also has access to my face and fingerprints. As tech changes, usable biometric data will likely be captured by 3rd parties from a distance as well. I'll stick with something that I know and at least have some limited constitutional protection from being forced to divulge.
- the_snooze 3y agoThat's not what passkeys are though. The server isn't validating if you have a matching face. The server is only checking if you have the private key that corresponds to a public key registered to your account. The private key lives on your device, and may be encrypted under a PIN, password, or biometric. In all those cases, the decryption operation is strictly local. Let's say some crook makes a convincing copy of your face. With passkeys, that's still not enough to log in. They have to have your private key too.