5 ms·
It's not quite as bad, your average user with an iPhone or Android phone will be fine. Just scan a QR code on the Windows machine and log in with the phone. Th
by lima 2y ago
It's not quite as bad, your average user with an iPhone or Android phone will be fine. Just scan a QR code on the Windows machine and log in with the phone.
The problem is that the UX for this is extra super confusing, and people will end up with passkeys that aren't backed up anywhere and get locked out of their accounts.
- gpm 2y ago"Just"? You just added minutes of figuring out where your phone is and how to scan a QR code to a log in process.
- ylk 2y agoFind your phone: https://www.icloud.com/find/ https://www.icloud.com/find/ Scanning a QR code: https://support.apple.com/en-us/102680 https://support.apple.com/en-us/102680 The time investment could even be worth it, since "Signing in with a passkey is three times faster than using a traditional password and eight times faster than a password and traditional MFA", according to the article.
- doublerabbit 2y agoFind your phone: https://www.icloud.com/find/ https://www.icloud.com/find/ -> I have that turned off Scanning a QR code: -> My back-camera lens is shattered. Using the front is dodgy at best. I don't feel like I need fork out for an to upgrade as I use a digital camera if I want to take pictures. What about those don't use smart phones?
- ylk 2y agoRegister a passkey on a different device or get a hardware key or whatever. Or call Microsoft support and complain to them. This doesn’t feeling like an honest discussion anymore.
- Prickle 2y agoIt absolutely is a Valid question. At the end of the day, the problem with passkeys Is that they are explicitly negatives for common people. Have a broken phone camera? Cannot scan qr codes. Lost the phone? Cannot log into vital modern day accounts like email. Your house burned down, and the passkey device with it? Say goodbye to literally everything. Homeless (temporary or otherwise) persons, random local government sweep just trashes everything you own. Bye bye to the passkey again.
- brokenmachine 2y agoYou're going to need some technology if you expect to interact with technology.
- Prickle 2y agoRight, but unlike a passkey, my password doesn't discriminate based on the device I use. If my phone explodes like a Samsung surprise, and my laptop turns into a spicy pillow; I can in the worst case scenario, still log in via the local library PC. I could borrow a device from a friend, or buy a second hand Thinkpad and use that. That is to my knowledge, not possible with a passkey device.
- ylk 2y agoThere are syncable and hardware-bound passkeys and you are free to use a password manager that syncs your passkeys. iPhones don’t even let you create a passkey with the built in password manager if you have synchronisation disabled. I don’t know for sure if Google does the same but I expect them to. If you’re remembering all your passwords there’s a good chance they’re terrible, you frequently re-use them or both. That really helps attackers e.g. when they use leaked passwords to run credential stuffing attacks on your employer. You just wrote two comments bashing a technology you admit you didn’t properly educate yourself about.
- Prickle 2y ago
- vel0city 2y agoYou do it once the first time you log in, then add another passkey for the service to the laptop. Now you don't need your phone to log in. Also, if you lose your phone, you can log back into the service on your new phone with your laptop.
- indrora 2y agoI don't have many things against passkeys for corporate accounts, but I don't think we're going to fully destroy passwords in the personal space. To the hardline Passkey-for-everything advocates, I pose the following situation: In your sleep, your house has burned down. You have zero devices, and your backup keys are stuck in a building you do not have access to for another several hours. You have made it out of your home with: Your wallet, containing $20 cash, a handful of slightly melty credit cards, an ID that is almost readable, and your keys. The credit cards are fucked and will need to be replaced. Your ID is mostly readable. This is the situation that I pose for most people to try and get undone from. I then amp it up another notch: you have no job and are unemployed currently. You cannot make use of any insurance system as you have been deemed "impossible to insure" due to your status. You currently live in a cardboard box behind a restaurant in downtown. And before you go "why would a homeless person need email", it's required for lots of services, as is a phone number that can at least have voicemail at it (this is a service that Futel^1 provides in some places). You can't assume that physical artifacts will continue being in the possession of a dishomed person. One of the common reasons for losing all your personal effects in this situation is the state literally taking everything down to your clothes away^2. ^1 https://futel.net/ https://futel.net/ ^2 https://www.realchangenews.org/news/2024/06/05/sweeps-tripled-2023 https://www.realchangenews.org/news/2024/06/05/sweeps-triple...
- janalsncm 2y agoAll of this makes me realize that availability is my biggest risk. My passwords are all 30 character random alphanumerics and I have none of them memorized.
- indrora 2y agoThis is, ironically, why I ended up with 1password over bitwarden: Their recovery process is down to "You can recover with paper, or another member of your family with access can break you into jail to get your account back up." I have tested this process with my partner. the only thing that I cannot replace is the TOTP token to add new devices (however this is bypassed when recovering from paper). I have legitimately considered etching the recovery data into a small glass (borosilicate) dish using selective laser etching.
- 015a 2y agoWhat if the passkey was generated on Windows and you're trying to sign in to iOS?
- hedora 2y agoIt’s your fault for not carrying your desktop and a camping battery with you. Just install a webcam on it and scan the qr code iOS displays. /s
- jesseendahl 2y ago>and people will end up with passkeys that aren't backed up anywhere and get locked out of their accounts. I don't know why this is such a common misconception about passkeys. Account recovery flows are generally entirely unaffected by moving from passwords to passkeys. If a user forgets their password or passkey, they generally go through an email recovery flow and generate a new one.
- Wowfunhappy 2y agoWhy do we even have passkeys at this point? Just store a cookie and use email verification for adding new devices. ...this is sort of a rhetorical question, but also maybe not? Slack does it, as do some other services I can't think of off the top of my head. I feel like a lot of normal people who don't use password managers basically always use email resets when logging in from a new computer. The thing is, email was never designed for this purpose. Password managers are. I stay logged into my email client on my computer, but I have to retype my password to open my Bitwarden vault.