tekphloyd, to passkeys
@tekphloyd@social.lol avatar

oh no... something wrong with . I'm generating them with my Mac, and I can't use them on my iPhone… :sweat_blob:

ajkelkar, to passkeys
@ajkelkar@mastodon.social avatar

Yubico has a cyber week 50% off sale on a second key https://www.yubico.com/de/store/2023/cyber-week/

iamkale, to passkeys

If you've heard me talking about WebAuthn and "hints" recently it's been in reference to this https://blog.millerti.me/2023/11/15/webauthn-sneak-peek-hints/

guilhermedea, to react
@guilhermedea@masto.ai avatar

Spent the entire holiday studying. Still having lots of difficulty with React, my head just can't wrap around the syntax of this thing.

At least I finished setting up my old laptop with Ubuntu. Thanks to passkeys on @1password, setting all my apps and browsers was a breeze. It's nice to live in the future!

brown, to random

Am I right in assuming that only one hardware bound passkey can be stored for a given domain on a FIDO security key? Since they’re discoverable you can’t keep there more than one account for domain, because you can’t choose which one to send.

brown,

Apparently I'm wrong, I tried and it works, which confuses me since the rpID is the only bit of data that the relying party is required to pass to the authenticator and it coincides with the domain. So, how do you avoid disclosing multiple for the same domain?

tychotithonus, to passkeys

Well, that's the source of the key I found on eBay. How did I not hear about these new security keys sooner??

https://mastodon.online/@9to5google/111415878503051725

"Google’s new Titan Security Keys let you store passkeys"

https://9to5google.com/2023/11/15/titan-security-key-passkey/

And the Google blog post says they hold up to 250 passkeys:

https://blog.google/technology/safety-security/titan-security-key-google-store/

Front of bubble pack of the new key.

timcappalli, to random

Happy to see orgs ditching passwords, but this is not the way...

timcappalli,

@adamcodega it's a terrible user experience. I'd prefer just u/pw over this, but really are the answer.

avolha, to infosec Polish

Co to jest passkeys, jak tego używać i czy jest to rozwiązanie lepsze niż hasła - opowiadał podczas wczorajszego webinaru @kacperszurek, zapis poniżej:

https://www.youtube.com/watch?v=h0tvYVKR-ro

Link bez śledzenia: https://yewtu.be/watch?v=h0tvYVKR-ro

#infosec #cyberbezpieczenstwo #passkeys

avolha,

Kolejny film o - tym razem nakręcony przez @mateuszchrobok. Warto się zapoznać:

https://www.youtube.com/watch?v=FrE3VuAOLc4

Link bez śledzenia: https://yewtu.be/watch?v=FrE3VuAOLc4

varjolintu, to passkeys

In the midst of the Passkeys hype, a quick reminder for browser makers that developers would definitely benefit from an open API that could be used to listen WebAuthn/Passkeys requests directly in a friendly way. Currently every password manager browser extension injects JavaScript to all web pages because they don't have any other option.

Ping @mozilla

mspsadmin, to passkeys

If you've ever wondered about and , this was a very in depth look.

https://www.yubico.com/blog/a-yubico-faq-about-passkeys/

I see lots of benefits, but also some risk. The rush to make logins easier, seems to be lowering the security bar. Storing passkeys in makes me a bit nervous because it seems to rely on a single authentication. Just using a password out of 1PW still needed 2FA if I didn't mark the device trusted. For some services, I never store trust. 2FA always.

eff, to passkeys
@eff@mastodon.social avatar

promise to prevent . What are they and how do they work? https://www.eff.org/what-is-a-passkey

timcappalli, to passkeys
craignewmark, to passkeys
@craignewmark@mastodon.social avatar
slink, to passkeys
@slink@fosstodon.org avatar

#tls client certificates have failed. how about we gold plate them and rename to #passkeys ?
#infosec

glynmoody, to random
@glynmoody@mastodon.social avatar

EU-wide digital wallet: MEPs reach deal with Council - https://www.europarl.europa.eu/news/en/press-room/20231106IPR09006/eu-wide-digital-wallet-meps-reach-deal-with-council this is an absolute disgrace, it will open up everyone in EU to invisible, unstoppable government surveillance. shame on @EU_Commission and @Europarl_EN details: https://www.techdirt.com/2023/11/03/eu-tries-to-slip-in-new-powers-to-intercept-encrypted-web-traffic-without-anyone-noticing/

kkarhan,

@quincy @thomasjorgensen @lobingera @glynmoody in fact didn't they try countless times to force shit that noone wants onto people, from to removing the to "" aka. mandatory that one can't disable...

Let's not forget - like all - was a collaborator, is subject to and and thus not only capable but able and willing beyond the legally mandated minimums to do so.

DON'T TRUST GOOGLE - or anyone!

mstankiewicz, to mastodon Polish
@mstankiewicz@pol.social avatar

Jestem na takim etapie, że nie bałbym się opublikować do mojego konta Wam wszystkim.
Dlaczego? Bo używam Kluczy bezpieczeństwa (albo po prostu Kluczy czy, po angielsku, ). Oprócz fizycznych kluczy jest to na ten moment najbezpieczniejsza metoda logowania i weryfikacji dwuetapowej.
Przechowuję je na dwóch urządzeniach i dzięki temu czuję się bezpiecznie.
A tutaj jakiś o tej technologii: https://secfense.com/pl/blog/passkeys-szybki-i-latwy-przewodnik-po-uwierzytelnianiu-bez-hasla/

bitwarden, to passkeys
@bitwarden@fosstodon.org avatar

New! Manage #passkeys inside your Bitwarden vault! Use the latest in secure passwordless technologies with the Bitwarden browser extension. Learn more in this blog and by joining the webcast on Nov. 9: https://bitwarden.com/blog/bitwarden-launches-passkey-management/

#security #cybersecurity #passwordmanager #passkey

koehntopp, to passkeys

OK, so...

only lets me create a on the desktop, not on mobile

only lets me add a new passkey on mobile, not on desktop.

Even after logging in with passkey, PayPal requests a TOTP token additionally.

When i try to send a paymen, PayPal needs to "confirm my identity". ("WhatsApp" - WTF???)

I have rarely seen a bigger mess and security theatre. PayPal, do better. You should be one of the leaders of secure enduser friendly authentication.

ezlin, (edited ) to Discord

actually did a fantastic thing for account and I am stoked!

CHECK IT OUT!

Hardware security key bayyybeee!

and it doesn't require ANY other 2FA method to be used!

Oh I am an excited little nerd.

edit: Bonus, this does NOT require a paid account!

pb4000, to passkeys

#Passkeys have a lot of confusion and valid criticism against them. However, there is one huge benefit that I feel like no one is talking about: they effectively eliminate password breaches as we know it!

#security #cybersecurity #passwords #technology

🧵1/2

iamkale, to random

It looks like BitWarden is following suit with 1Password and returning "uv:true" in WebAuthn authentication requests even though the user isn't prompted for anything more than to confirm the use of a passkey. The unlocking of the vault is considered the user-verifying event...

As an end user I appreciate the streamlined experience. But as an RP I'm disappointed - what if vault unlock occurred 5/10/30 minutes prior? Someone could cruise by someone's desk when the vault is unlocked and auth as the vault owner and the RP would be none the wiser 😢

It's a tough middle point that passkey providers have to try and find 🥴

danie10, to bitwarden
@danie10@mastodon.social avatar

Bitwarden begins adding passkey support to its password manager

Although Bitwarden now supports storing and logging in using passkeys from its browser extensions, it’s not currently possible to store passkeys in the company’s mobile app. According to Bitwarden’s FAQ, this feature is “planned for a future release.”

Fina ...continues

See https://gadgeteer.co.za/bitwarden-begins-adding-passkey-support-to-its-password-manager/

endlessmirth, to passkeys

But I don't want to use . I have a password manager, it's fine. Faangs and other vampire squids are going to 1) pat themselves on the back for supporting a standard, 2) make it super easy to generate keys that work with their proprietary gunk, and 3) make it difficult to export those keys. Nope.

governa, to bitwarden
@governa@fosstodon.org avatar

Adds Support for - Release Notes :bitwarden:

https://bitwarden.com/help/releasenotes/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • provamag3
  • mdbf
  • ngwrru68w68
  • modclub
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • JUstTest
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • tester
  • osvaldo12
  • everett
  • cubers
  • tacticalgear
  • anitta
  • megavids
  • Leos
  • cisconetworking
  • lostlight
  • All magazines