Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
21–30 of 525 posts
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#22So their vision of the future is that to do anything online, one MUST have a phone (ahem, portable wiretap)? And they're going to be keeping my secrets for me, for my own good? I'm not sure I'm down with any of that.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#23Not a great thing to see the big three once again, driving the standards here. You should be worried. But as long as the ridiculous SMS 2FA is removed or replaced by something better, then fine. But we'll see how this goes. From the web side of this standard, this also tells me that Mozilla has no influence anywhere and will be the last ones to implement this standard in Firefox. Oh dear.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#24I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
No, because it should be evident by now that a phone is a personal computer, not to be shared with other people.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#25I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
No, because it should be evident by now that a phone is a personal computer, not to be shared with other people.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#26I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#27Dumb question: why are biometrics being used to replace the password , shouldn't the biometric replace the username ?
It sounds like it's still a one factor authentication system, but different.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#28I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
No, because it should be evident by now that a phone is a personal computer, not to be shared with other people.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#29I’m sure people way smarter than me have this figured out, from the Google post: > When you sign into a website or app on your phone, you will simply unlock your phone — your account won’t need a password anymore. > Instead, your phone will store a FIDO credential called a passkey which is used to unlock your online account. The passkey makes signing in far more secure, as it’s based on public key cryptography and is…
Normal usage would require a reauthentication - i.e. FaceId or TouchId - to produce the passkey.
I think the more general point is that "able to unlock the phone" is not / should not be the same as "I have verified that this is you" for sensitive applications and information.
Re: Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard
#30Does anyone here know what privacy/tracking issues are with this standard?
FIDO2 privacy is actually pretty good and well thought out. There's a theoretical risk of a website sending authentication challenges for two different accounts and having both assertions signed by the same credential, basically correlating those accounts together, but this is unlikely to weaken collective privacy at scale.