5 ms·
The danger is that you now can no longer use netflix without they're approved hardware? Of course, that's essentially already the case with netflix, but this be
by array_key_first 11mo ago
The danger is that you now can no longer use netflix without they're approved hardware? Of course, that's essentially already the case with netflix, but this becomes dicey when services that actually matter take this approach.
And then suddenly you're debanked.
- stavros 11mo agoNo, we're talking about logins, not usage. Can someone explain to me a case where logging in only with an approved authenticator would be problematic?
- geonineties 11mo agoHow exactly are you going to use a service that requires login if the login requires an authorized device you don't have?
- stavros 11mo agoOK, so what's the scenario? Netflix wants to make me not use their service? Surely there are easier ways to do that than to make a new auth standard?
- throwawayffffas 11mo agoIt's not really Netflix. Its Microsoft, Apple and Google. So say goodbye to using teams on Linux. Using Microsoft365 on any hardware that is not Microsoft approved. Or logging in to your bank without an iPhone or an android. We will surely complain but the bank will say that we only support secure devices and that means iPhones and Android, and how come you are making a big deal about it just buy one of these two everyone else has one.
- joshuamorton 11mo ago> Or logging in to your bank without an iPhone or an android. This is already possible (and common!) many banking apps, for better or worse, use device attestation features that require varyingly official copies of android. Were you already complaining about this?
- throwawayffffas 11mo agoIt's definitely worse. Banking credentials are stolen the old fashion way, phishing.
- joshuamorton 11mo agoI'm not sure what your point is here. How credentials are stolen today is irrelevant to the fact that today, right now, at this very moment, banks can and do already do the thing you're worried will be possible only due to the prevalence of passkeys.
- throwawayffffas 11mo agoOh my point is that their device attestation thing is security theater. It's clearly just for getting that iso certification. It's a power play by the platform vendors. The vendors are literally saying: We now have this "security" feature and banks have to use it to be compliant and it only works on our platforms, so I guess you have to use our platform unless you want to be unbanked.
- joshuamorton 11mo agoI mean, I would agree that it's not a particularly useful thing for consumer-phone-bank usecases, but that doesn't mean the feature is bad (or harmful). Just to be clear, no one is saying > banks have to use it to be compliant nor are they saying > it only works on our platforms As far as I know, if systems were to use attestation it would be in a lot of senses more open than what attestation is available today (in the sense that more devices could use it). But also I don't think anyone who works on passkeys is saying banks need to support FIDO attestation to be "compliant".