• Ooops@feddit.org
    link
    fedilink
    arrow-up
    30
    ·
    1 day ago

    "UK.gov begins killing off passwords for 23 million users

    vs.

    “The NCSC is encouraging users to switch, although passwords aren’t disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so.”

    Clickbait bullshit.

  • ranandtoldthat@beehaw.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    1 day ago

    Way too soon for anything that takes itself seriously to rely on passkeys.

    Passkeys are just a mess right now. Despite attempts to improve things, it’s gotten even worse over the past few years. The tech giants, password managers, browsers and websites have just not been willing to work well with one another through FIDO. I’m guessing the tech giants are most at fault but who knows.

    • audaxdreik@pawb.social
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 hours ago

      I keep saying this myself. I feel bad because there is a real problem they are solving (phishing) but ultimately it is an overly technical solution to an extremely human problem. They’re only as strong as their weakest recovery method and the inability for the average user to understand the technical implementation and ramifications takes power away from a personally held secret (problematic as that may be) and shifts it towards more platformization.

      It all just makes me vaguely uncomfortable in ways I have a problem fully articulating.

    • HarkMahlberg@kbin.earth
      link
      fedilink
      arrow-up
      4
      ·
      1 day ago

      I haven’t been following what these are or why they’re flawed. It looks to me like they’re taking Two Factor Auth, and removing one of the factors (the password). Now all you need is a device? If the device is lost or itself compromised, isn’t that still a single point of failure?

      • jnod4@lemmy.ca
        link
        fedilink
        English
        arrow-up
        6
        ·
        1 day ago

        You can backup a 2fa code on so many multiple managers at the same time, how the hell can one backup a pass key?

        • cmnybo@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          2
          ·
          21 hours ago

          Use a password manager that supports passkeys. Then you can back them up and sync them between all of your devices the same way you do with your passwords and 2fa keys.

    • TehPers@beehaw.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Assuming it’s £600/day total (which would make more sense than per person), that’s a bit over £200k/yr. It isn’t that much taken relatively, but it’s still money that can be spent somewhere better, and it’s enough to make a noticeable impact depending on how it’s used.