4 ms·
I don't get the passkey hate in the comments. I just store it in Bitwarden, and it syncs across my phone, laptop and desktop. Has been a better experience than
by Synthetic7346 1mo ago
I don't get the passkey hate in the comments. I just store it in Bitwarden, and it syncs across my phone, laptop and desktop. Has been a better experience than passwords
- 7bit 1mo agoOne note: Organisations can chose to have device-bound passkeys, so Bit warden would no longer be a valid passkey store.
- vaylian 1mo agoYou mean via attestation? If the company that you work for requires you to use a device-bound key, then they should also issue you a FIDO hardware token.
- 7bit 1mo agoNo, not via attestation. That's a different concept. Device-bound just ensures they passkey stays on the device where it was created. Bit warden in that sense is not device-bound but synced.
- EvanAnderson 1mo agoThe company I work for requiring device-bound passkeys is the least of my concern. Once the idea of device-bound passkeys being "more secure" gets into the public consciousness as being "more secure" it'll be like the idiotic websites that don't permit pasting into password fields.
- OkayPhysicist 1mo agoThe elevator pitch for passkeys is okay. A bit more complexity than we should be pushing non-technical users, but fine. A deeper dive into the the actual implementation reveals that the whole thing is a massive vendor lock-in hell-hole, pushed by megacorps who want nothing short of complete domination of your life. First off, sites are extremely pushy about replacing your perfectly good password with a passkey, but then they hide the process for adding additional passkeys, if they offer it all, deep in the settings somewhere. Guess what? That means people locking themselves out of their accounts. All the time. Sites should not be able to choose to only accept 1 passkey. The process of making multiple keys should have been entirely client side. It's nothing short of malpractice to coerce users into setting up exactly 1 passkey. Second off, the villains in the consortium decided that sites should be able to discriminate about what vaults they want to accept. This is a massive recipe for vendor lock in, and it's already been wielded as cudgel against KeypassXC for having the audacity to let users access their own keys, by threatening to add them to a blacklist. Sites ought to have ZERO say over what vault I use. If I want my vault to be a powershell script with a bunch of hard-coded values, that should have been my prerogative. Instead, you're trusting a bunch of oligopolic assholes to deign your vault acceptable. It is much, much, much easier for non-technical people to understand the concept of "don't give strangers your passwords" than it is to get them to understand that by giving into the nagging prompts that their email is showing them every single time they log in, they've effectively locked themselves into only ever logging into their email on this computer. Don't use passkeys, make sure your less-technical peers understand the danger of passkeys, and don't let the holier-than-thou, patronizing ghouls of the consortium spread their propaganda unopposed.
- tatersolid 1mo ago> sites are extremely pushy about replacing your perfectly good password with a passkey Your password was never “perfectly good” because it is easily phished. Even with TOTP or a push notification app as MFA. Phishing is an huge risk even for “expert” technical users, and such phishing is the cause of a huge number of breaches and supply-chain attacks.