kornel, to passkeys
@kornel@mastodon.social avatar

Authentication with U2F keys (AKA Fido or Yubikey) works well for me. It's phishing-proof and as easy as tapping a button. I'm not in a rush to try #Passkeys.

linuxuserspace, to linux
@linuxuserspace@mastodon.social avatar

Today in User Space
🖥️We host even MORE #Linux #containers
🔑Fall in love with #Passkeys
🦜Look at the #History and #Hack of #Xz
📀And unbreak Open Source #Software

#OpenSource #FOSS #LinuxUserSpace
https://www.linuxuserspace.show/418

governa, to passkeys
@governa@fosstodon.org avatar

2.7.8 Release Adds Enhancements to 🔒

https://news.itsfoss.com/keepassxc-2-7-8/

governa, to bitwarden
@governa@fosstodon.org avatar
srueegger, to passkeys German
@srueegger@swiss.social avatar

🔑 Passkeys: Die passwortlose Zukunft ist da!

Bist du es leid, dir unzählige zu merken? Die neueste Technologie der verspricht eine einfache Lösung.

Aber wie nah sind wir wirklich an dieser Zukunft? In meinem neuesten Blogbeitrag werfe ich einen kritischen Blick auf die aktuellen Herausforderungen von Passkeys.

Erfahre mehr über die Zukunft der digitalen Authentifizierung. 🚀💻

https://rueegger.me/2024/05/05/die-herausforderungen-der-passkeys-eine-zukunft-ohne-passwoerter/

83r71n, to Cybersecurity
@83r71n@ioc.exchange avatar

Google's passkeys, introduced in 2022, have become a popular and secure alternative to traditional passwords, being used over 1 billion times across 400 million-plus Google accounts. These passkeys, which rely on fingerprints, face scans, or PINs for authentication, are faster and more resistant to phishing than passwords. Google plans to integrate passkeys into its Advanced Protection Program, enhancing security for high-risk users. Additionally, third-party password managers like Dashlane and 1Password can now support passkeys, further expanding their use. The technology is supported by major companies like eBay, Uber, PayPal, and Amazon, indicating a shift towards passkey-based authentication as a more secure and efficient method.

https://blog.google/technology/safety-security/google-passkeys-update-april-2024/

jela, to passkeys German
@jela@social.tchncs.de avatar

Das hat ihre Richtlinien zur digitalen Identität für die Verwendung von ergänzt. US-Behörden können synchronisierbare und gerätegebundene Passkeys verwenden, um eine Phishing-resistente zu ermöglichen.
https://www.nist.gov/blogs/cybersecurity-insights/giving-nist-digital-identity-guidelines-boost-supplement-incorporating

jnareb, to passkeys
@jnareb@fosstodon.org avatar

I'm very disappointed that passkeys (allegedly) got enshittified before I could start to try to use them: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

schizanon, to passkeys
@schizanon@mastodon.social avatar

PassKeys seem like a bad idea. Google backs them up to the cloud, so if your Google account is compromised then all your private keys are compromised. I don't see how that's an improvement over password+2FA at all.

Now security keys I get; keep the private key on an airgapped device. That's good. Hell I even keep my 2FA-OTP salts on a YubiKey.

#passkeys #fido2 #webauthn #yubikey #2fa #otp #authentication #cryptography #security #passwords #passkey #password #securityKey #google

scottjenson, to passkeys
@scottjenson@social.coop avatar

Am I the only one confused by ? They feel clunky, it's not at all clear what is going on, and honestly doesn't feel any different than a password manager (but somehow worse)

I really don't even understand what is going on under the hood. Are there any good explainers out there?

TechDesk, to passkeys
@TechDesk@flipboard.social avatar

Google has kicked off World Password Day by announcing that over 400 million users have used passkeys since the tech giant rolled them out, logging over one billion authentications between them.

Passkeys rely on device-based authentication, often using a fingerprint scanner or face recognition, which makes logging in faster and more secure. Despite this, our passwordless future still feels some way off — @theverge considers why.

https://flip.it/vvLM1A

osma, to passkeys
@osma@mas.to avatar

I wish this wasn't a correct conclusion.

"At this point I think that Passkeys will fail in the hands of the general consumer population. We missed our golden chance to eliminate passwords through a desire to capture markets and promote hype."

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

grantpotter, to passkeys

If you really want put them in a password manager you control. But don't use a platform controlled passkey store, and be very careful with security keys. https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

JetForMe, to passkeys
@JetForMe@geekstodon.com avatar

I recently implemented Passkey support in one of my apps, and ran into some limitations of the spec. I had no idea it was this bad.

I had assumed I’d be able to get my passkeys out of my Apple devices, but hadn’t put any real thought into that.

“Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then by locking all their credentials into your platform, and even better, credentials that can't be extracted or exported in any capacity.”


https://infosec.exchange/@firstyear/112335226264184474

katzenberger, to passkeys
@katzenberger@social.tchncs.de avatar

@firstyear , the author of webauthn-rs, on (I don't agree with everything in the article):

»starting to agree - a password manager gives a better experience than passkeys.[…]

Get something like bitwarden or if you like self hosting get vaultwarden. Let it generate your and manage them. If you really want passkeys, put them in a password you control. But don't use a platform controlled passkey store, and be very careful with security keys.«

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

publicvoit, to apple
@publicvoit@graz.social avatar

"#Apple Keychain has personally wiped out all my #Passkeys on three separate occasions. There are external reports we have received of other users who's #Keychain Passkeys have been wiped just like mine."

"At this point I think that Passkeys will fail in the hands of the general consumer population."

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

My conclusion would be different though. Instead of going back to classic #passwords, I recommend using #FIDO2 hardware tokens wherever you can as 2nd factor.

#security

kas, to passkeys
hateaid, to passkeys German
@hateaid@troet.cafe avatar

yqUxBV#_\jfVyD!mZ8RH7]Te8jqKA![? – auch dieses Passwort kann geknackt werden. Deshalb bieten immer mehr Dienste [ als Login-Alternative an. Lest hier, wie sie genau funktionieren und was sie so sicher macht: https://hateaid.org/sicheres-passwort/?mtm_campaign=tsp-it-sicherheit-passkeys&mtm_kwd=mastodon

Dieses Projekt wird unterstützt vom Bundesministerium der Justiz.

ChristosArgyrop, to random
@ChristosArgyrop@mstdn.science avatar

2FA is driving me nuts. I think I may be going back to Subversion or even CVS.

mjgardner, (edited )
@mjgardner@social.sdf.org avatar

@ChristosArgyrop Until those systems start using instead of and , I'm afraid you're stuck.

For now, keep safe your 2FA/ seeds (the QR code or string you add to an authenticator app). As you saw in https://social.sdf.org/@mjgardner/112287092545124096 I favor but there are other options depending on your use cases.

protonprivacy, to apple
@protonprivacy@mastodon.social avatar

and have hijacked passkeys to keep users locked into their walled gardens.

Here's how we can make work for everyone: https://proton.me/blog/big-tech-passkey

nsa, to passkeys
@nsa@hachyderm.io avatar

New post on choosing the right timeout value in !

tl;dr

  • design your challenge-response protocol to allow for a very long value
  • whatever you do, don't leave it to the default value

https://satragno.com/blog/webauthn-timeout/

protonprivacy, to macos
@protonprivacy@mastodon.social avatar

ICYMI, here are the March top articles on our blog ⬇️

🎭 Now you can create hide-my-email aliases directly in the #ProtonMail web app: https://proton.me/blog/hide-my-email-aliases

🖥️ The Proton Mail #macOS & #Windows apps have been released, with the #Linux app becoming available in beta: https://proton.me/blog/proton-mail-desktop-app

🔑 #ProtonPass now supports #Passkeys on all platforms: https://proton.me/blog/proton-pass-passkeys

❓ If you don’t know what they are, don’t worry, we’ve got you covered: https://proton.me/blog/what-is-a-passkey

1 / 2

fell, to SmartHome
@fell@ma.fellr.net avatar

I stopped messing with client certificates and went back to good old HTTP basic authentication for my little digital light switch panel.

It's a shame nobody cares about TLS client certificates. With a bit more effort we could've gotten rid of passwords a long time ago.

I wish there was something like SSH keys for the web.

Yeah I know, Passkeys are a thing... but also not really.

ianRobinson, to passkeys
@ianRobinson@mastodon.social avatar

What account should I use as my first experimental login to convert to using passkeys?

PayPal?

I know you don't know what systems I use, so this is a bit of a meaningless question. But do you know of any popular systems that a lot of people use that now support passkeys?

Preferably ones that can be stored and used by 1Password 8. Maybe I should do 1Password first if they support passkeys.

danie10, to opensource
@danie10@mastodon.social avatar

Proton Pass now supports passkeys on all devices and plans: Beating Bitwarden to mobile devices

Passkeys are an easy and secure alternative to traditional passwords that can help prevent phishing attacks and make your online experience smoother and safer.

Unfortunately, Big Tech’s rollout of this technology prioritized using passkeys to loc ...continues

See https://gadgeteer.co.za/proton-pass-now-supports-passkeys-on-all-devices-and-plans-beating-bitwarden-to-mobile-devices/

#opensource #passkeys #ProtonPass #security #technology

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • kavyap
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • ngwrru68w68
  • Youngstown
  • everett
  • slotface
  • rosin
  • ethstaker
  • Durango
  • GTA5RPClips
  • megavids
  • cubers
  • modclub
  • mdbf
  • khanakhh
  • vwfavf
  • osvaldo12
  • cisconetworking
  • tester
  • Leos
  • tacticalgear
  • anitta
  • normalnudes
  • JUstTest
  • All magazines