5 ms·
Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an extern
by Rucadi 2y ago
Passwords are a pain in the ass, I just wished that having a cryptographic key installed in your device (and linked to it) to login to stuff or having an external crypto-device to login was easier and more common.
For local access, biometrical is fine, and a "super-secure" password for if something happens that can only be used once would be the way.
- dsego 2y agoI want to be able to tie digital credentials to my identity so if they are compromised or I loose access I can recover them by providing my national ID documents. Similar how I do with my bank app, I go to the bank, show my ID, sign some forms and reset all the creds. I don't have to fear loosing access. On the other hand if I loose my google account I'm screwed, all my other services depend on either my email address or google 2fa keys to prove my identity.
- spacebanana7 2y agoI fear that mixing government IDs to commonly used digital credentials could invite lots of privacy violations from businesses and governments. It'd be much easier for porn & social media ID laws to be enforced. Which could be abused by adtech and law enforcement.
- 05 2y ago> a "super-secure" password for if something happens that can only be used once With 99.99% chance you forget it before you ever get to enter it because humans forget things they never use :)
- Lanolderen 2y agoYou can store it in paper with your other important documents. It's not unstealable but if someone nicks your document folders you're spending two weeks redoing/reissuing everything anyway.
- IlikeKitties 2y agoJust use a KeepassXC and you are 99% there. Add some Browser extension that synchs with it and only use randomly generated passwords.
- techjamie 2y agoI've taken a liking to using a self-hosted Bitwarden instance via vaultwarden, and it's been a pretty good experience. The vaultwarden server is only accessible through my Tailscale network for extra security. https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden
- PaulKeeble 2y agoI use KeepassXC as well and it works well enough. Its still not as clean as just an SSH key login which we could have done on the web years ago and would make everyone’s life easier.
- shakna 2y agoBiometrics are really not fine. They're somehow supposed to be some permanent marker of who you are, but that's really not how it works in the real world. You physically change. I've broken any biometrics recognising me in a dozen different ways, this year alone. Cut open my finger, changing my fingerprint. Head surgery for melanoma gave me a scar so facial recognition doesn't work anymore, blood vessel burst in my eye, so iris scan changed. And so on. They're fine for a convenience, but that's it. They're nothing more than a pin, and you will have to fall back to password or authenticator or something else, sooner or later.
- nbadg 2y agoAlso, even if they work as desired, if they're ever compromised [1], you're permanently unable to use that form of authentication, or permanently vulnerable to services that use and/or require it. [1] https://en.wikipedia.org/wiki/Biometrics#Data_security https://en.wikipedia.org/wiki/Biometrics#Data_security
- Ajedi32 2y agoAgain, biometrics are fine for local access. If you cut your finger or scar your face just use your backup method (maybe a pin, maybe a different finger) to get in and update the scan. And if someone steals your fingerprint they can't use it without having physical access to your device, because again, this is for local access. For remote authentication you use a private key accessed via the local system (which you are already authenticated to using biometrics).
- shakna 2y ago> a "super-secure" password for if something happens that can only be used once That does not imply a pin or password for easy fallback. That implies something harder, that os self-destructive on use.
- vikingerik 2y agoThere's also this failure case: I know a pair of sisters who look and sound identical enough that they can unlock each other's phones with face and voiceprint recognition.
- vel0city 2y agoI use these a lot when available, often called "passkeys".
- PaulKeeble 2y agoWe could have been using SSH key logins for decades at this point but no we had to go and use usernames and passwords everywhere. I don't want a key limited to a single device I just want a strong key that can automatically login to a website. The technology has existed for longer than the internet it just needs to become the norm.