3 ms·
I don't have many things against passkeys for corporate accounts, but I don't think we're going to fully destroy passwords in the personal space. To the hardlin
by indrora 2y ago
I don't have many things against passkeys for corporate accounts, but I don't think we're going to fully destroy passwords in the personal space. To the hardline Passkey-for-everything advocates, I pose the following situation:
In your sleep, your house has burned down. You have zero devices, and your backup keys are stuck in a building you do not have access to for another several hours. You have made it out of your home with: Your wallet, containing $20 cash, a handful of slightly melty credit cards, an ID that is almost readable, and your keys. The credit cards are fucked and will need to be replaced. Your ID is mostly readable.
This is the situation that I pose for most people to try and get undone from. I then amp it up another notch:
you have no job and are unemployed currently. You cannot make use of any insurance system as you have been deemed "impossible to insure" due to your status. You currently live in a cardboard box behind a restaurant in downtown.
And before you go "why would a homeless person need email", it's required for lots of services, as is a phone number that can at least have voicemail at it (this is a service that Futel^1 provides in some places). You can't assume that physical artifacts will continue being in the possession of a dishomed person. One of the common reasons for losing all your personal effects in this situation is the state literally taking everything down to your clothes away^2.
^1 https://futel.net/ https://futel.net/ ^2 https://www.realchangenews.org/news/2024/06/05/sweeps-tripled-2023 https://www.realchangenews.org/news/2024/06/05/sweeps-triple...
- janalsncm 2y agoAll of this makes me realize that availability is my biggest risk. My passwords are all 30 character random alphanumerics and I have none of them memorized.
- indrora 2y agoThis is, ironically, why I ended up with 1password over bitwarden: Their recovery process is down to "You can recover with paper, or another member of your family with access can break you into jail to get your account back up." I have tested this process with my partner. the only thing that I cannot replace is the TOTP token to add new devices (however this is bypassed when recovering from paper). I have legitimately considered etching the recovery data into a small glass (borosilicate) dish using selective laser etching.
- 0cf8612b2e1e 2y agoWhy glass over something presumably more durable? Ease of smashing if the gestapo break down the door?
- indrora 2y agoDurability to cost ratio. I can get 90mm borosilicate petri dishes for $10 that I can be pretty certain won't melt into a glop, plus having a "contained" object allows me to have tamper seals that are much harder to violate (nail polish). Thus, "password recovery material, TOTP QR code, and an SD card with essential documentation" can be passed to next of kin easily.
- Kuinox 2y agoOn bitwarden you can also put an emergency access with an emergency contact: https://news.ycombinator.com/item?id=42413539 https://news.ycombinator.com/item?id=42413539
- fragmede 2y agoFor mainstream people uninterested in such things, this isn't a solution, but since the question was posed to "me", one way back into digital life that is not passkey specific is https://dangerousthings.com/product/apex-flex/ https://dangerousthings.com/product/apex-flex/
- vel0city 2y ago> and your keys Ah, so no worries then. I've still got a passkey for all the services I really care about. If I'm not supposed to have cloud-synced credentials like so many here dislike with those implementations of passkeys, chances are the copies of my password safes and my SSH keys to the VPS are all cooked as well.
- Wowfunhappy 2y agoHeck, forget about the fire. You're traveling in a foreign country without your laptop when your wallet and phone are stolen. You can probably get to a public computer, but how do you get into your email? This situation strikes me as much more likely than getting hacked. Hence I will never use passkeys unless forced, and if forced I will do everything in my power to switch to another service. Same for forced 2FA as far as I'm concerned.