Earlier quoted context omitted.
At least on Bitwarden you can just edit the domain if that comes up a lot for you (or even add multiple domains to a password). I'd rather do that than copy/paste on a regular basis. Honestly I can't say I ever copy/paste.
Yeah, I do this too, but many people I know wouldn't even think about the fact that they could do that, or why they would. They just know that whatever password manager they use doesn't find the password but if they search for it, it's there. So they do that and get on with their lives, inadvertently opening up an avenue for phishing.
Passkeys: A shattered dream
671–680 of 789 posts
Re: Passkeys: A shattered dream
#672Earlier quoted context omitted.
You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…
This all sounds like "it's technically possible, but it's a huge huge hassle and sticking with passwords is significantly easier".
I have so many keys scattered everywhere that I would need an excel sheet to keep track of them. I regret not doing that already .. or perhaps I regret using passkeys at all. I am still trying to figure that out.
Re: Passkeys: A shattered dream
#673Earlier quoted context omitted.
I’m really not sure the “only real solution” is every human needs to selfhost a password manager. That’s ill-advised; an extreme take. The vast majority of the population will do a worse job on the availability and security of a selfhost solution than 1Password, whose core business and value proposition is password management. I’m a very happy user of 1Password for Families and consider it the likely the best ~$50 a…
I'm a happy user of 1password also. But I'm not touching passkeys until they let me export them. Last time I checked, it was a platform lock-in.
Re: Passkeys: A shattered dream
#674Earlier quoted context omitted.
A few weeks ago, I was unable to log in to Google on a new device with my 2FA token (Yubikey) because Google insisted on authenticating with a passkey/resident key, but the token had only been set up with non-resident TOTP or whatever it's called (and had been working properly in this mode for over a year). I was able to log in on another device and register the Yubikey with a passkey/resident key, but it was really…
It's a Google sign-in workflow problem. I've seen the same issue more than once - for whatever reason it decides that this one way of signing in is the one that you want to use right now, and it can be impossible to back out until some timeout kicks in.
Re: Passkeys: A shattered dream
#675Earlier quoted context omitted.
PIN+limit is still a much worse user experience than a password: - a PIN is hard to memorize, so people are more likely to use personally-relevant or common numbers, whereas a password can be easily be both complex and memorable - it's easy to burn through even 10 login attempts through any combination of temporary/permanent disability, stress, being drunk, damaged device... - a wipe-after-failed-attempts system is t…
PINs can include all characters just like a password. They're called PINs for historical reasons. (This does depend on the specific key/protocol.)
Re: Passkeys: A shattered dream
#676Earlier quoted context omitted.
1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...
> 1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account They used to offer their apps offline and you could "host" it anywhere. Venture Capital ruined them.
Re: Passkeys: A shattered dream
#677Earlier quoted context omitted.
PINs can include all characters just like a password. They're called PINs for historical reasons. (This does depend on the specific key/protocol.)
Great, so we are back to passwords then
Re: Passkeys: A shattered dream
#678Earlier quoted context omitted.
I use 1Password which supports Passkeys, and don’t have an issue across mobile or desktop. I don’t get what the issues people have really are. I never experience them (fortunately!).
1Password is a closed-source, cloud-hosted service. At any time, for any reason, they can close and delete your account, leaving you high and dry. Self-hosted, multi-device password managers are the only real solution. Thankfully, Vaultwarden and KeePassXC fill this role perfectly. Now if we could just get the other providers that require insecure email/SMS 2FA to follow suit, that would be great...
Re: Passkeys: A shattered dream
#679The biggest issue with passkeys is that I just can't trust the companies offering them. They are locked into the platform for reasons that are ostensibly security but often indistinguishable from platform lock-in. If you make a passkey on an Apple device as far as I can tell it will never leave that device, ever, and there is no way to change this. Of course this means you can never be phished for your credentials bu…
You are able to share an Apple passkey to any nearby Apple device at any time using AirDrop. Passkeys can also be used cross-platform during sign in via an NFC/Bluetooth handshake initiated by QR code. Additionally, passkeys are just a synced-via-cloud implementation of FIDO2, an open standard that has other implementations you may feel more comfortable using. For someone who requires being able to sign in to, say, G…