3 ms·
I don’t like how tokens have gradually evolved from a secure 2F device that you carry with you (Yubikey etc) to a single factor “passkey” that’s built in to you
by iamnothere 8d ago
I don’t like how tokens have gradually evolved from a secure 2F device that you carry with you (Yubikey etc) to a single factor “passkey” that’s built in to your computer/phone, or worse, a password manager with export capability.
It should always have remained a second factor device. It’s not impossible to teach people to use these, European banking did it for years. There’s just no will to do it.
- dalyons 8d agoIt’s because we have effective biometrics now, so the need to carry around an inconvenient limiting physical 2nd factor is obsolete (for the vast majority of regular use cases)
- izacus 8d agoWe also have devices with yubikeys built-in now.
- deleted 8d ago[deleted]
- sikozu 8d agoI 100% agree with this. I have physical passkeys, one attached to my keys and another on my desk at home and I absolutely hate software based passkeys. Every single time I'm asked for a passkey it always ask me if I want to use my Apple Keychain first and I wish I could default to physical.
- dalyons 8d agophysical 2fa should be an option, but i can never agree that we should force billions of regular people to use a harder to use and more inconvenient system that they have already indicated they dont want to use, for some mild security benefits
- iamnothere 8d agoWhy not? We “forced” everyone to use SMS/email second factor, now we’re moving towards “forcing” passkeys, and European banks used to “force” the use of an electronic HOTP/TOTP token. Decoupling logins from the big cloud providers is a clear win for freedom and protection against abuse. People are frequently cut off from their cloud accounts for whatever reason, and I expect this problem to increase as global disorder increases. (To be clear, I don’t think people should be legally forced to use tokens, but I do think that industry should be heavily encouraged in that direction.)
- kccqzy 8d agoIf a user doesn’t have a second factor, what should their first and only factor be? The passkey people are trying to posit that a passkey is better than a password as the only factor.
- iamnothere 8d agoSecond factor should be gradually ushered in everywhere over a period of years, starting with banking, until it becomes second nature for users. This would effectively end concerns over strong or reused passwords, and would make phishing incredibly difficult. Under this scenario, the first factor can be a short password or even a PIN.