Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
 exu   ( @exu@feditown.com )  to TechnologyEnglish · 1 year ago

Passwords have problems, but passkeys have more

world.hey.com

external-link
message-square
17
link
fedilink
  • cross-posted to:
  • technology@lemmy.ml
66
external-link

Passwords have problems, but passkeys have more

world.hey.com

 exu   ( @exu@feditown.com )  to TechnologyEnglish · 1 year ago
message-square
17
link
fedilink
  • cross-posted to:
  • technology@lemmy.ml
We had originally planned to go all-in on passkeys for ONCE/Campfire, and we built the early authentication system entirely around that. It was not a simple setup! Handling passkeys properly is surprisingly complicated on the backend, but we got it done. Unfortunately, the user experience kinda sucked, so we ended up ripping it all out...

cross-posted from: https://feditown.com/post/744772

alert-triangle
You must log in or # to comment.
  •  stravanasu   ( @pglpm@lemmy.ca ) 
    link
    fedilink
    English
    arrow-up
    19
    ·
    1 year ago

    The current security philosophy almost seems to be: “In order to make it secure, make it difficult to use”. This is why I propose to go a step further: “In order to make it secure, just don’t make it”. The safest account is the one that doesn’t exist or that can’t be accessed by anyone, including its owner.

    •  🐝bownage [they/he]   ( @bownage@beehaw.org ) 
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      Yeah but then we can’t sell you ppu licenses.

      •  stravanasu   ( @pglpm@lemmy.ca ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        😂

  •  ranandtoldthat   ( @ranandtoldthat@beehaw.org ) 
    link
    fedilink
    English
    arrow-up
    13
    ·
    1 year ago

    I use a password manager with passkey support and still disabled all my passkeys. The user experience for passkeys is so much worse even when support exists.

    •  state_electrician   ( @state_electrician@discuss.tchncs.de ) 
      link
      fedilink
      English
      arrow-up
      8
      ·
      1 year ago

      Really? I just used a passkey for the very first time with Google and Bitwarden and it worked quite nicely. What about passkeys is worse for you?

      •  ranandtoldthat   ( @ranandtoldthat@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Just answered in a reply to a different comment.

    •  Mihies   ( @Mihies@programming.dev ) 
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      What’s the problem with combination of manager and passkeys?

      •  ranandtoldthat   ( @ranandtoldthat@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        Just answered in a different comment.

    •  ericjmorey   ( @ericjmorey@beehaw.org ) 
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      I’d like to hear more about the specifics if the issues you ran into. I keep delaying my options to start using passkeys because it’s a lot to take in at once and the only services implementing them seem to be the most important ones that I really don’t want to experiment with my ability to acess them. I haven’t even been looking at the details of each service’s implementation.

      •  ranandtoldthat   ( @ranandtoldthat@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 year ago

        It’s a combination of issues. First is compatibility issues. Like logging in on mobile web or app with a passkey doesn’t reliably work for me. It might have been due to the password manager, but for some things the option wasn’t even there afaict. If I’m going to really switch to passkeys, I want it to work more reliably.

        The second is usability. Passwords in a password manager are a 2 click entry on the username or password form field. Password managers have streamlined this system over the past decade.

        Passkeys, ironically, required more steps when pulling from the password manager, including required clicks in less convenient places. I hope these types of issues get ironed out eventually.

        •  Mihies   ( @Mihies@programming.dev ) 
          link
          fedilink
          arrow-up
          1
          ·
          1 year ago

          Yeah, both feels like password manager issues. Which one do you use?

    •  Lem453   ( @Lem453@lemmy.ca ) 
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      How do you login from a device that doesn’t have Bitwarden on it if you have passkeys.

      For example a friend’s computer etc

      With a password I can type the 20 or so digits of the password. Can’t really be done with a passkey as far as I know

      •  ranandtoldthat   ( @ranandtoldthat@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 year ago

        When I was trying out passkeys, things allowed either passkey or password still. But yes, I think this need partially reduces the security benefit of passkeys.

  •  smeg   ( @smeg@feddit.uk ) 
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    1 year ago

    Using a security key as a password manager passkey seems to resolve this issue (I think?), but I guess the issue is more a problem for the casual user who wouldn’t bother with a security key!

    •  ericjmorey   ( @ericjmorey@beehaw.org ) 
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Can you elaborate on what it means to use a security key as a password manager? I’m not sure if I understand what you mean.

      •  smeg   ( @smeg@feddit.uk ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        Whoops, I meant “passkey”, I’ll edit my original comment

  •  Boomkop3   ( @Boomkop3@reddthat.com ) 
    link
    fedilink
    arrow-up
    2
    ·
    1 year ago

    Normalize having a usb key on your keychain! Like a yubikey or something

Technology

technology

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@beehaw.org

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:

  • Free and Open Source Software
  • Programming
  • Operating Systems

This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 169 users / day
  • 696 users / week
  • 2.58K users / month
  • 6.33K users / 6 months
  • 5.07K local subscribers
  • 41.1K subscribers
  • 5.52K Posts
  • 98.5K Comments
  • Modlog
  • mods:
  •  Chris Remington   ( @remington@beehaw.org ) 
  •  alyaza [they/she]   ( @alyaza@beehaw.org ) 
  •  TheRtRevKaiser   ( @TheRtRevKaiser@beehaw.org ) 
  •  gyrfalcon   ( @gyrfalcon@beehaw.org ) 
  •  rs5th   ( @rs5th@beehaw.org ) 
  •  coldredlight   ( @coldredlight@beehaw.org ) 
  •  Leigh   ( @SemioticStandard@beehaw.org ) 
  •  TheRtRevKaiser   ( @TheRtRevKaiser@kbin.social ) 
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code