4 ms·
An alternative viewpoint to consider is how much pain and suffering passwords cause large companies or identity providers. One example: Large organizations oft
by jf 2y ago
An alternative viewpoint to consider is how much pain and suffering passwords cause large companies or identity providers.
One example: Large organizations often spend $1m/yr on password resets alone.
- vorpalhex 2y ago"Hello, IT, my toddler accidentally dropped my phone in the ocean. I can't log into anything now. No, I can't restore my iCloud keys onto my Windows laptop. Please help." I suppose corporate gets to overnight you a yubikey in 2-3 days?
- deleted 2y ago[deleted]
- jesseendahl 2y ago>Hello, IT, my toddler accidentally dropped my phone in the ocean. I can't log into anything now. It's clear that you are making assumptions without doing any research... Yes you can. See "Recovery security" section of this article: https://support.apple.com/en-us/102195 https://support.apple.com/en-us/102195 >No, I can't restore my iCloud keys onto my Windows laptop. Yes you can — see this article: https://support.apple.com/guide/icloud-windows/set-up-icloud-passwords-icw2babf5e03/icloud https://support.apple.com/guide/icloud-windows/set-up-icloud...
- vorpalhex 2y agoRead the KB carefully. 1. Your windows pc doesn't have a SecureEnclave (tpm2.0 doesn't count!) so no, you can't do PassKey recovery only password recovery. 2. You can only do iCloud recovery to another Mac/iOS device. In other words, not your windows PC. Hope you have a spare Macbook hiding out.
- 015a 2y agoThat's why I very specifically said: Passkeys solve problems that corporations have, by moving the problems on to consumers. Our industry was done writing reliable, quality software years ago, so it shouldn't come as any surprise that we want to keep going in that direction. Passwords have such an obvious, fantastic, beautiful quality in how when all else fails you can verbally say out loud "my password is X C J 5 4..." Its the ultimate form of reliability: non-digital, spoken or written language. Passkeys throw that away. I don't care about any of the other arguments. Our industry wants to build less reliable software, so we built passkeys. I don't know why we're obsessed with building things that are less reliable instead of more reliable, but we are. Its sad, its insane, and frankly I'm getting so damn tired of trying to push for reliability every day and instead seeing Microsoft just throw weight around, get hacked, throw weight around again, get hacked again, and somehow still reap respect for their position in matters of security.