3 ms·
Where is the line exactly though? If the password manager put up a big red notice when trying to export in plain text is that enough? If not, why not? I am sym
by tuckerman 1y ago
Where is the line exactly though? If the password manager put up a big red notice when trying to export in plain text is that enough? If not, why not?
I am sympathetic to the intent but the words of Patrick Henry come to mind too often in conversations like these. I love passkeys and appreciate secure defaults but I feel strongly that user freedom is a more fundamental requirement than preventing phishing attacks.
- AndrewDucker 1y agoBecause many end users will ignore that. And this technology is set up to prevent end users from hurting themselves, even if that constrains technologically capable ones.
- tuckerman 1y agoMy values are such that it’s inappropriate for a few folks at companies and random consortiums to make that decision on behalf of all society. If KeepassXC wanted to enforce that world view for the safety of their users, it’s their right, but this is essentially a threat of blacklisting an entire password manager for adding a feature demanded by their users (who likely predominantly used by technically savvy users at that).
- palata 1y ago> but this is essentially a threat of blacklisting an entire password manager I don't think they could blacklist the entire password manager. They can't prevent it from giving you a username/password... Refusing some passkeys is, to me, similar to refusing passwords that are too short. It may make sense to only accept passkeys backed by a secure element. Companies already force their employees to use a specific MFA app, because they don't want to trust any app out there.
- tuckerman 1y agoWhat if websites start adopting passkey-only with instead of offering a username/password option? We could live in a world where services are inaccessible unless you use Google/Apple/1Password/etc as your password manager
- palata 1y ago> We could live in a world where services are inaccessible unless you use Google/Apple/1Password/etc as your password manager If services want to force you to use whatever authentication they want, they can. That's what already happens with any service that is serious about security. In big companies, you have to use their authenticator app, their mail client, their messaging system, etc. Often it's Microsoft software. Banks have their own systems, etc. Now, if a service allows you to use a passkey instead of their own 2FA app, I'd say it's a win. I'm happier using a security key than a Microsoft authenticator. But if they give up on using their own app, they may well set conditions on the passkey you use. And that condition may be "it has to be backed by a trusted secure element". You won't be able to use a passkey that's deemed unsecure just like right now, you already are not able to just use a weak password with some services. Again, I'm not saying that being forced to depend on TooBigTech is not a problem: it very much is. But nothing says that services have to do it with passkeys: they could (and should) also accept secure passkeys that don't come from TooBigTech. But they still have a say in what they find secure or not, and that part is okay.
- tuckerman 1y agoI don’t think we should create standards that make it easier for companies to erode user freedoms and I’d support legislation to restrict what certain companies can/can’t do (banks, Google/Apple, etc) The discussion about what happens in big companies is completely unrelated to this discussion. In that case the company is the user. They can do/enforce whatever they want and nobody is having any freedoms infringed.
- palata 1y ago> The discussion about what happens in big companies is completely unrelated to this discussion It's not, in that they have plenty of technological solutions to address their security concerns. Passkeys don't make it easier. > I don’t think we should create standards that make it easier for companies to erode user freedoms We want some degree of security in many services (typically our bank). And we generally can't have it all. Security is a compromise.