3 ms·
Problem with auth methods is the protocol fatigue for the average user. And that even includes some tech savvy people. I have been in the process of teaching my
by figassis 2y ago
Problem with auth methods is the protocol fatigue for the average user. And that even includes some tech savvy people. I have been in the process of teaching my family to use password managers. I subscribed to 1Password family, added everyone and then added the app to their devices, setup their Face IDs/Touch IDs, set the app as default password manager on their devices, added it to their browsers, etc, just to make it as simple as possible for them to just be safe.
They’re still having a hard time grasping the concept of 1 password per site. Or that password do not need to be memorable or the name of their pet plus their birth date. So they fight it.
Often they call me saying some service is broken, emails aren’t working, etc, and I ask for their password and they show me a list of account passwords in their notepad app, bc they were trying to replicate 1 password in their minds, because they absolutely do not trust what they do not understand.
I for one do not like magic links, prefer regular otp, especially because I can add it to my 1Password. I don’t like magic links because it adds an extra step of opening my email app, clicking a link and opening a new tab. It breaks my flow, so I tend to avoid services with magic links unless it’s only for account recovery.
Passkeys, I have skimmed the implementation, and flows, but I can’t get over the lock in and lock out potential.
So going back to fatigue, if my relatives are still in the password manager training phase, I’m definitely not going to confuse them with magic links, much less with passkeys. I will wait, and wait, and wait, until this all settles down and we have a gold standard, and everyone falls in line. Average users do not need the latest, “safe enough” is enough for them.
- 1oooqooq 2y agoa text file on the desktop for sites like these are better than any alternative to be honest. at least they aren't reusing their bank password everywhere.