• Gork@sopuli.xyz
        link
        fedilink
        arrow-up
        18
        ·
        edit-2
        3 hours ago

        The code is at the bottom of the can and can only be seen be shining a flashlight down it. This completes Step 1 of the verification.

        Oh and it changes your pee color so it can reveal the passkey pisskey verification QR code on the urinal in front of you to complete Step 2 of the verification.

        • rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          9
          ·
          3 hours ago

          Half a cryptographic key that you can’t easily give to someone over the phone by accident.

        • Pasta Dental@sh.itjust.works
          link
          fedilink
          arrow-up
          6
          arrow-down
          1
          ·
          3 hours ago

          a very long password that (ideally) is only bound to a single device, requires a second identifier (biometric, PIN, password) and that is phishing resistant.

          • ☂️-@lemmy.ml
            link
            fedilink
            arrow-up
            10
            arrow-down
            2
            ·
            3 hours ago

            bound to a single device

            yay vendor lock in. google or meta password manager salivating.

            • Zink@programming.dev
              link
              fedilink
              arrow-up
              4
              ·
              2 hours ago

              Bitwarden has been working great with me as sits transition to passkeys, even big corporate ones.

              But yeah in practice, google and facebook are going to probably dominate because they are the easy + free option.

              • lime!@feddit.nu
                link
                fedilink
                English
                arrow-up
                4
                arrow-down
                2
                ·
                edit-2
                2 hours ago

                thus rendering them redundant, because their strength is being bound to a single physical device. if they’re portable, they’re as good as asymmetric key pairs.

                • 4am@lemmy.zip
                  link
                  fedilink
                  arrow-up
                  3
                  ·
                  2 hours ago

                  Their strength is being half a cryptographic key, not that they’re device bound.

                  That was a “requirement” that big tech wanted, to force you to be dependent on TPM storage, so you’d be forced to use a Trusted™ device and OS. It was made optional after pushback from basically everyone else.

                  Password managers support Passkeys now. Bitwarden and KeePassX among others.

                  As long as I trust that my password manager is secure, and as long as I use a strong master password or (better) have a hardware key to unlock it, it is way more secure than a password, and I can still install Linux without losing my logins.

              • ☂️-@lemmy.ml
                link
                fedilink
                arrow-up
                1
                ·
                2 hours ago

                i’m assuming most people will use the default, which will probably be google lock in anyway.

          • Kaiserschmarrn@feddit.org
            link
            fedilink
            arrow-up
            3
            ·
            3 hours ago

            bound to a single device

            Bitwarden let’s you sync your passkeys between devices. And you can also unlock your vault with one stored on a physical security key.

        • nearhat@lemmy.zip
          link
          fedilink
          arrow-up
          2
          arrow-down
          2
          ·
          edit-2
          2 hours ago

          Ooh-la-la, someone’s gonna get laid in college.

          Edit: This is a joking reference from a Rick and Morty episode (S02E06).

          • ☂️-@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            3 hours ago

            i don’t get what this has to do with college, or getting laid at all but sure.

            • nearhat@lemmy.zip
              link
              fedilink
              arrow-up
              2
              ·
              2 hours ago

              Oh, I’m sorry. It’s a reference to a Rick and Morty episode. I thought that’s what you were referring to.