7 ms·
> But I agree: TooBigTech has TooMuchPower. Passkeys are here to improve your login security! All you have to do is give complete control over your ability to
by coldpie 6mo ago
> But I agree: TooBigTech has TooMuchPower.
Passkeys are here to improve your login security! All you have to do is give complete control over your ability to log in to a service to one of three American big tech companies. Yay!
- palata 6mo agoOr you spend 5 minutes reading about them and use a passkey you actually own? Many times, people choose TooBigTech. People are generally waaaay too lazy to even consider spending some brain cycles on that.
- coldpie 6mo agoUnless the service you are trying to log in to requires you to only use an approved authenticator, as is explicitly supported by the spec[1]. [1] "To be very honest here, you risk having KeePassXC blocked by relying parties." https://github.com/keepassxreboot/keepassxc/issues/10407#issuecomment-1994182200 https://github.com/keepassxreboot/keepassxc/issues/10407#iss... More examples here https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/#:~:text=It%27s%20Still%20Vendor%20Lockin https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...
- palata 6mo agoRight, that sucks. But the service could also only allow you to use the Google SSO, it's not really a problem coming from the passkeys...