Live data from Hacker News

Passkeys and Modern Authentication

lucumr.pocoo.org

211–212 of 212 posts

Re: Passkeys and Modern Authentication

#211
post #43

Earlier quoted context omitted.

Security people are generally pretty positive on Passkeys. Eliminating passwords has been the white whale of information security for over 3 decades. Practitioners are generally positive about FIDO2 (Yubikeys are fetish objects for them). I think message board people would probably be surprised at security practitioner attitudes towards Apple and Google authentication lock-in (locking my team into Google authenticati…

> I think message board people would probably be surprised at security practitioner attitudes towards Apple and Google authentication lock-in We're not surprised, but I think many of us are horrified. I think it's a culture clash, partly between Free Software and Enterprise communities, partly between developers and security professionals. Given that it's a culture clash, I don't actually see any resolution that will…

Many security professionals suffer from a horrible case of Boyscoutism where they think snuffing out freedoms is okay because bad people will never be doing the snuffing out.

Re: Passkeys and Modern Authentication

#212
I am a security professional and I have an obsession about authentication (along other obsessions).

While I understand and love passkeys, I spend so much time and WTFs on trying to get a passkey for some accounts (that say "what about using a passkey instrad" and omit to say how the fuck to make one), or tell me to connect with a passkey I have no idea where it is.

This is sooo frustrating.

And then I have to explain it to my wife pretending that everything is under control while she suspiciously look at me for yet another annoyance I put on her.

Post reply on HN