fell, to SmartHome
@fell@ma.fellr.net avatar

I stopped messing with client certificates and went back to good old HTTP basic authentication for my little digital light switch panel.

It's a shame nobody cares about TLS client certificates. With a bit more effort we could've gotten rid of passwords a long time ago.

I wish there was something like SSH keys for the web.

Yeah I know, Passkeys are a thing... but also not really.

#http #smarthome #tls #ssl #password #authentication #ssh #passkeys #passkey #https

ianRobinson, to passkeys
@ianRobinson@mastodon.social avatar

What account should I use as my first experimental login to convert to using passkeys?

PayPal?

I know you don't know what systems I use, so this is a bit of a meaningless question. But do you know of any popular systems that a lot of people use that now support passkeys?

Preferably ones that can be stored and used by 1Password 8. Maybe I should do 1Password first if they support passkeys.

#AskMastodon #Passkeys

danie10, to opensource
@danie10@mastodon.social avatar

Proton Pass now supports passkeys on all devices and plans: Beating Bitwarden to mobile devices

Passkeys are an easy and secure alternative to traditional passwords that can help prevent phishing attacks and make your online experience smoother and safer.

Unfortunately, Big Tech’s rollout of this technology prioritized using passkeys to loc ...continues

See https://gadgeteer.co.za/proton-pass-now-supports-passkeys-on-all-devices-and-plans-beating-bitwarden-to-mobile-devices/

#opensource #passkeys #ProtonPass #security #technology

HistoPol, to passkeys
@HistoPol@mastodon.social avatar
fission, to passkeys
bsi, to passkeys German
@bsi@social.bund.de avatar

Nie mehr komplizierte Passwörter! Mit könnt ihr endlich auf sie verzichten – die Einrichtung ist einfach und die basiert auf einem kryptografischen Verfahren. Mehr dazu: 👉 https://www.bsi.bund.de/dok/1107468

dominic, to passkeys French

Les #passkeys sont enfin désormais supportées par #ProtonPass de @protonprivacy sur tous les appareils compatibles et les types de comptes (autant gratuits que payants). Ne manque plus que la possibilité de classer les données par dossiers ou étiquettes (labels).

https://www.lesnumeriques.com/appli-logiciel/proton-pass-integre-le-support-des-passkeys-sur-tous-les-appareils-n219742.html

mjgardner, to passkeys
@mjgardner@social.sdf.org avatar

Shots fired at @bitwarden: “And many #password managers only support #passkeys on specific platforms…”

When will we be able to create and use #Bitwarden passkeys outside of the browser extension? https://mastodon.social/@protonprivacy/112134037609531372

Belganon, to passkeys French
@Belganon@mastodon.social avatar

, le gestionnaire de de @protonprivacy, prend désormais en charge les . Peu de sites utilisent déjà cette technologie, mais le nombre augmente de plus en plus. Une nouvelle couche de pour vos connections, plus performante et sûr que la

https://proton.me/blog/proton-pass-passkeys

protonprivacy, to passkeys
@protonprivacy@mastodon.social avatar

By popular request, #ProtonPass now supports #passkeys — on all devices, for everyone.

Passkeys provide a secure and convenient alternative to passwords.

✨ Save, store and edit passkeys in Proton Pass.

https://proton.me/blog/proton-pass-passkeys

floyd, to passkeys

#Passkeys: reinventing TLS client certificate authentication that is proxyable and all private keys stored in the cloud and then of course the connection is only on one side TLS authenticated and therefore MITM-able from the other (aka proxyable, yes yes CAs and stuff but ya' know). Does this sound about right?

frankel, to passkeys
@frankel@mastodon.top avatar
cryptgoat, to passkeys German
@cryptgoat@digitalcourage.social avatar

Die neue Version vom freien #Passwortmanager #KeePassXC ist da und bringt neben vielen Detailverbesserungen Unterstützung für #Passkeys: https://keepassxc.org/blog/2024-03-10-2.7.7-released/
#Passwörter #Sicherheit #Security #FreeSoftware

tuxwise, to passkeys
@tuxwise@social.tchncs.de avatar

2.7.7 released:

Don't be shy, @keepassxc - post about it, here, on Mastodon 😉

https://keepassxc.org/blog/2024-03-10-2.7.7-released/

Wiulinu, to passkeys German
wilhelm, to firefox

Now that my favorite browser and beloved password manager both support decided to spent some time checking them out.

And boy oh boy are passkeys not ready yet in Firefox. I love Firefox and wish them well, but they really need to do some testing. There are major issues.

creation is straight-up broken and resulting in reproducible crashes on both google.com and webauthn.io

Issue is filed.

wilhelm, to passkeys

Now that all major desktop browsers support caniuse.com/passkeys is there an effort happening to create browser level APIs open to everybody to ensure passkeys can be used effectively?

While open sourced their implementation blog.1password.com/passkey-cra… of -crates the question is: is any work happening on Passkey APIs for browser extensions (i.a. password managers) to use.

While it is great to see big tech move the needle on this and announce their implementations and push this technology, it is a pity those efforts seem to focus around siloing and limiting passkey usage to their implmenetation / tech.

For example Apple makes it impossible for e.g. @keepassxc to generate passkeys in the browser.

Are there plans to work on open browser APIs? is there any public info / efforts you are aware of and can share @rmondello? Specifically for it would be great if Passkey creation / authentication could be used via Apple APIs.

dethos, to security
@dethos@s.ovalerio.net avatar

"Passkeys - Threat modeling and implementation considerations"

https://slashid.com/blog/passkeys-security-implementation/

cendyne, to passkeys
@cendyne@furry.engineer avatar

Hmm, does ebay not let you set up more than one passkey? It says "Passkeys" after setting up one with faceid... And then has the option "Turn off" instead of "Edit"

#passkeys

douginamug, to passkeys
@douginamug@mastodon.xyz avatar

I genuinely forgot my phone pin for ~12 hours.

A pseudo-pattern, because #grapheneOS doesn't allow actual patterns on the basis they are less secure 🙃

Managed to shift the 2 starting numbers to one side. After ~60 brute-force attempts from this incorrect starting position, my intuition/desperation lead me to the correct start position -> success 👴

Super insecurity-inducing episode. (And what about accident induced memory loss? Dementia? Perhaps biometric #passkeys solve it all /s) #infosec

darkghosthunter, to php
@darkghosthunter@mastodon.social avatar

Finally! I updated my Passkeys (WebAuthn) package for Laravel, and that includes a totally new JS helper.

https://github.com/Laragear/WebAuthn

majorlinux, to passkeys
@majorlinux@toot.majorshouse.com avatar

Is Sony finally taking security seriously?

Sony is making it easier to sign into your PlayStation - Desk Chair Analysts

https://dcanalysts.net/sony-is-making-it-easier-to-sign-into-your-playstation/

#Passkeys #PlayStation #Security #Sony #Gaming #Tech #DCA

xeophin, to Switzerland
@xeophin@swiss.social avatar

WIRED: is trying to establish a unified login for Swiss authorities.

WIRED: It is built on /WebAuthn.

TIRED: It doesn't support .

🤦🏻‍♂️

Edent, to security
@Edent@mastodon.social avatar

Where are the U2F Rings?

The FIDO specification defines a form of Universal 2nd Factor (U2F) when users log in to a system. Rather than relying on one-time codes sent via SMS, or displayed on a phone screen, these are physical hardware tokens which are used to supplement passwords. When used with websites, this technology is also known as WebAuthn.

I use a USB thumb-drive sized hardw

https://shkspr.mobi/blog/2022/02/where-are-the-u2f-rings/

#/etc/

Edent,
@Edent@mastodon.social avatar

Some more weirdness with #Google and #PassKeys.

I've successfully added an #NFC ring to my Google account - although it shows up as an iCloud key (WTF?)

But when I try to sign in with it - it says it doesn't recognise the key. If I try to add it again on my previous device, it says it is already there.

Fuckery is afoot!

Edent,
@Edent@mastodon.social avatar

I've spent a month wearing my MFA token on my finger and… it has been great (mostly).

After using my username and password, I tap my NFC ring onto my phone / laptop.
It doesn't replace passwords, and I'm comfortable with that.

Once configured, most services worked fine - although PayPal only allows one token registered at a time.

There's still a lack of support from banks etc. And the NFC occasionally accidentally triggers my phone.

https://shkspr.mobi/blog/2024/02/giving-the-finger-to-mfa-a-review-of-the-z1-encrypter-ring-from-cybernetic/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines