4 ms·
Use a password manager (that isn't too buggy and/or suck) and you get the same thing for both TOTP and passwords.
by diggan 1y ago
Use a password manager (that isn't too buggy and/or suck) and you get the same thing for both TOTP and passwords.
- koakuma-chan 1y agoNpm can't force people to use password manager
- diggan 1y agoNor does TOTP+password lock you to one authentication provider indefinitely. Tradeoffs :)
- maltee 1y agoYou can always register a new passkey with the site if you want to switch authentication providers, can’t you?
- diggan 1y agoYeah, I guess that'd work if I had a couple of accounts, but since there a bunch of them, I really need proper import/export to feel comfortable with moving to it. I just know I'd punt the task of migrating everything if I have to go account-by-account to migrate away. Considering that today it'd add work for me today, and future work, with no additional security benefits compared to my current approach, it just don't seem worth it.
- vel0city 1y agoI've got passkeys from multiple "authentication providers" available on all of my devices. This isn't a tradeoff.
- ljlolel 1y agoYou can if you just force passwords longer than people can memorize or even want to write down (assigned 24+ characters)
- koakuma-chan 1y agoIt's just gonna be on a sticky note hanging on the screen or under keyboard
- hu3 1y agocareless people just copy paste those
- ApolloFortyNine 1y agoAs mentioned elsewhere in this thread, the password manager failing to autofill is hardly unheard of.
- diggan 1y agoAs also mentioned elsewhere in this submission, it doesn't matter how often autofill breaks/works. There are two cases where it breaks: The accounts not showing up in the password manager modal, and the website autofill not working. The first is what prevents phishing, the second doesn't really matter to prevent phishing or not. The idea is that if your password manager doesn't show the usual list of accounts (regardless if the actual autofill after clicking the account works or not), you double-check the domain.
- yawaramin 1y agoYes, the idea you are presenting is that the human being must manually check for mistakes. As should be clear by now, this idea does not work at scale. Passkeys will automate and enforce the check, removing human error from the equation.
- diggan 1y ago> Yes, the idea you are presenting is that the human being must manually check for mistakes. Not at all? The password manager handles that automatically, have you never used a password manager before? > Passkeys will automate and enforce the check What happens to the passkey when the origin changes, is it automatically recognising it as the new domain without any manual input? Curious to see what magic is responsible for that
- yawaramin 1y ago> Not at all? Yes: '...you double-check the domain.' That's manually checking for mistakes. > What happens to the passkey when the origin changes, The passkey won't work at all. You will just have to create a new one.