4 ms·
> a new problem Yes, the problem exists in multiple "places" and all schemes are different balances. There are many different kinds of "security". Each suits
by nonrandomstring 2y ago
> a new problem
Yes, the problem exists in multiple "places" and all schemes are
different balances.
There are many different kinds of "security". Each suits different
needs, or addresses different threats. Not all are based upon
"identity" as a central concept. Not all are based on secrets. For
those that are, changing your secret from something you know to
something you own merely shifts a locus of trust and mode of use.
Passkeys (and ssh keys with passphrase) are a good solution in some
cases, where you use multiple end points which may be compromised. But
they are no better (and less flexible) than challenge response and one
time passwords and other elaborate password schemes that are a
superior access control secret in other situations [0].
The problem is that most people don't understand the quite subtle
interplay of factors. This is one area of cybersecurity education I'm
spending more time on because regulations are going to place more
emphasis on making good security choices (and not just accepting
vendor defaults).
Microsoft unilaterally deciding it thinks it knows what is "best " for
you accords with its clumsy patrician over-reach, and cover for a
pitiful security record in its products.
Perhaps one of the most important meta-security factors is that you be
able to select products that allow you to choose your security
parameters and how they interact as your situation and access habits
change. But that responsibility requires understanding.
[0] https://cybershow.uk/blog/posts/secrets https://cybershow.uk/blog/posts/secrets