Passkeys will come at a cost
571–580 of 600 posts
Re: Passkeys will come at a cost
#572Re: Passkeys will come at a cost
#573Re: Passkeys will come at a cost
#574Re: Passkeys will come at a cost
#575Re: Passkeys will come at a cost
#576Re: Passkeys will come at a cost
#577Re: Passkeys will come at a cost
#578Earlier quoted context omitted.
Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…
> But if you're running a privacy focused browsers I'm sorry but I was with you until here. if you're going to run a privacy enhanced browser and then complain that it has a privacy enhancing features which result in providers being more cautious because you have privacy enhancing features, then I'm not sure how to help you. I run anti-google adware on my main browsing identity but when sites give me shit I just turn…
There should be a middle ground. If I'm logging back in 2 minutes later from the same IP, using the same browser on the same is, just ask for the password. Or even better let me choose if I want to use that "phone auth" option in the first place.
Re: Passkeys will come at a cost
#579Earlier quoted context omitted.
Exactly, I'm seriously considering taking my business off google's ecosystem because of the unwanted "we've sent a notification to your phone" confirmation requirement. I could understand if they did that if I suddenly tried to login from the other side of the world, or let's say I always use Linux and suddenly my browser identifies as windows etc. But if you're running a privacy focused browsers (ungoogled chromium)…
>Then the whole "answer some questions" dance starts. Google literally does provide you with backup codes that they tell you to keep offline available, which is pretty common practice for any 2FA scheme.
Re: Passkeys will come at a cost
#580Earlier quoted context omitted.
> KeePass, which apparently supports them, who knew... Bitwarden, too. I no longer have to worry about not having my phone on me, or even having to take it out of my pocket.
>I no longer have to worry about not having my phone on me, or even having to take it out of my pocket. I mean, I appreciate the convenience but can't help feel like this is cheating... The whole point of 2fa was to verify you had the 2fa device and this basically defeats that.
I do also have the ability to bootstrap Bitwarden access on a new device without an existing device -- the two factors then being "knowing my passphrase" and "having my security key".