4 ms·
While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolatin
by elteto 16d ago
While the technology itself may be great (I don't really know since I don't use them) it has been co-opted by the tech conglomerates as another form of isolating and walling off users into their ecosystems.
And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. One of those "if you see them running that way you run the opposite way".
- spider-mario 16d agoIt’s a bit ironic that Apple is the one that lets you export them.
- rcxdude 16d agoThey're also not supporting device attestation which would allow websites to insist on particular implementations of passkeys.
- dingaling 16d agoThat's more because attestation breaks their passkey cross-device sync process, rather than out of benevolence.
- 93po 15d agoBut only to other approved apps
- spider-mario 15d agoNot as far as I’m aware? They of course require the target app to be compatible with the way they export them, but I don’t think they vet them manually. At the very least, on my phone, the apps it agrees to export to include Chrome and Bitwarden (the latter of which lets me export them further).
- mschuster91 16d ago> And honestly, nowadays, if tech companies are pushing really hard for something then that is an immediate red flag for me and it bears more scrutiny. The reason is the ever increasing number of hijacks of social media presences and code hosting portals, with the latter being a serious financial threat. Done right, passkeys stay in the Secure Enclave, at least for anything Apple and most of the Android sphere. There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s).
- iso1631 16d ago> There is no reasonable way to obtain login credentials for accounts protected by passkeys without physical access to the user's device(s). Click "I lost my device", enter contact, get a reset link via email/sms
- deleted 16d ago[deleted]
- terminalbraid 16d agoEmail and SMS are not reasonable and both have an extraordinary number of flaws.
- jmbwell 16d agoSo use the recovery codes. Or scan the QR code and auth from another device I’d buy that there are too many different confusing ways to recover from this situation, but not that it’s impossible
- Barbing 16d ago>use the recovery codes. Fun fact: Google can decide to reject these. Lose access to the original device, try to rely on recovery codes to login with known current password on family member’s device… nope!
- reddalo 16d agoExactly. That's why I'll never use passkeys: they're just another way to force us into a commercial walled garden. Passwords with 2FA are simply better and more freedom friendly.
- apexalpha 16d agoI just bought a passkey... It's a USB device, completely separate from any big conglomerates.
- reddalo 16d agoBut then you need to phisically carry it along with you everywhere you go, if you want to log into a service :/
- apexalpha 16d agoYes, it’s like a key. :) Though realistically I use a passkey for services I care about and a password manager for the rest.
- eikenberry 16d agoKeys can be copied very easily. It’s one of their primary features. Can you easily copy your USB key?
- jazzyjackson 16d agoYubikeys are Secure Enclaves designed to not be copyable
- eikenberry 15d agoRight. That's the flaw I was pointing out.
- krupan 16d ago
- alibrarydweller 16d agoI did a deep dive on this since progressively more places are taking a hard line about Passkeys. The most flexible, independence preserving thing to do is to use a third party password manager like Bitwarden, and make that the default passkey flow for your devices. If desired, you can self-host something like Vaultwarden so that you can both keep the keys independent of third parties and walled gardens and also propagate them to other client devices. To be clear I'd much rather not have learned / implemented any of this, and I don't use passkeys unless forced, but this seems like a valid coping strategy.