Earlier quoted context omitted.
Do you have some examples where people actually require attestation in 3rd party facing systems? Or is this purely "But in theory..." and you've dismissed all the very real problems with the alternatives because you're scared of a theoretical problem ? I always reject attestation requests and I don't recall ever having been refused, so if this was a real problem it seems like I ought to have noticed by now.
The Fido2 folks really really want things to be so secure and centralized, with so little user freedom, and they want to use attestation to do it. Here's a Fido2 member (Okta) employee saying "If keepass allows users to back up passkeys to paper, I think we'll have to allow providers to block keepass via attestation." https://github.com/keepassxreboot/keepassxc/issues/10407#iss... All because passkeys backup is deeme…
Emailing a one-time code is worse than passwords
641–650 of 816 posts
Re: Emailing a one-time code is worse than passwords
#642Earlier quoted context omitted.
A key part of the recent push for passkeys has been cross device syncing with your Google / Apple / whatever password manager account, so you end up in the same situation: if you can log in to Bitwarden to access your passwords, you can log in to your password manager to access your passkeys.
> A key part of the recent push for passkeys has been cross device syncing with your Google / Apple / whatever password manager account, so you end up in the same situation: if you can log in to Bitwarden to access your passwords, you can log in to your password manager to access your passkeys. Relying on Google/Apple is no better, with the stories of people losing access to their (Google in particular) account, and…
The State is always more difficult and dangerous to deal with than a private company.
Re: Emailing a one-time code is worse than passwords
#643What's quite annoying is how agressive most products are into forcing this method over regular email+pw / Social Logins. Let me use my 100 chars password!
Such long passwords are silly, they will be effectively truncated by the key length of the underlying cryptography.
If your password was 123lookatme, you could type 123lookaLITERALLYANYTHING and it would succeed.
Re: Emailing a one-time code is worse than passwords
#644Earlier quoted context omitted.
>"I’d rather granny needs to visit the bank to get access to her account again, than someone phishes her and steals all her money." More like abuelita gets robbed at gunpoint and made to unlock and clear out her bank account, then has no recourse at home because her device was taken. I live in a third world country and even 2FA simply isn't viable for me due to how frequent phone robberies are. I've had to do the pro…
A key part of the recent push for passkeys has been cross device syncing with your Google / Apple / whatever password manager account, so you end up in the same situation: if you can log in to Bitwarden to access your passwords, you can log in to your password manager to access your passkeys.
Please stop right there. I want a password manager that I fully control, and lives on my own infrastructure (including sync between devices). Not reliance on someone else's cloud.
Re: Emailing a one-time code is worse than passwords
#645Re: Emailing a one-time code is worse than passwords
#646I just deleted my gofundme because they kicked me into this cycle today. Somehow I've managed to have an account there and make contributions over the years, but now they wanted my phone number and an MFA code to proceed, and there was no opt-out. I went through it but then deactivated my account. I need less of this in my life, and gofuneme is not essential to my life. I'm in the rental market right now, and Zillow…
Re: Emailing a one-time code is worse than passwords
#647Earlier quoted context omitted.
> A key part of the recent push for passkeys has been cross device syncing with your Google / Apple / whatever password manager account, so you end up in the same situation: if you can log in to Bitwarden to access your passwords, you can log in to your password manager to access your passkeys. Relying on Google/Apple is no better, with the stories of people losing access to their (Google in particular) account, and…
So then the State can see what services I've signed up for, when and where? The State is always more difficult and dangerous to deal with than a private company.
Ridiculous.
Re: Emailing a one-time code is worse than passwords
#648Re: Emailing a one-time code is worse than passwords
#649Re: Emailing a one-time code is worse than passwords
#650[flagged]