• rumba@lemmy.zip
      link
      fedilink
      English
      arrow-up
      25
      ·
      1 day ago

      Half a cryptographic key that you can’t easily give to someone over the phone by accident.

    • Pasta Dental@sh.itjust.works
      link
      fedilink
      arrow-up
      19
      arrow-down
      1
      ·
      1 day ago

      a very long password that (ideally) is only bound to a single device, requires a second identifier (biometric, PIN, password) and that is phishing resistant.

      • ☂️-@lemmy.ml
        link
        fedilink
        arrow-up
        13
        arrow-down
        3
        ·
        1 day ago

        bound to a single device

        yay vendor lock in. google or meta password manager salivating.

        • Pasta Dental@sh.itjust.works
          link
          fedilink
          arrow-up
          2
          ·
          16 hours ago

          that’s not the point, passkeys are not vendor centric, they are a standard. you don’t want to duplicate a passkey for the same reason you don’t want to copy an SSH private key on multiple devices. it’s a security feature that allows disabling the account access in case the device becomes compromised (lost, stolen, infected, etc.)

              • ☂️-@lemmy.ml
                link
                fedilink
                arrow-up
                1
                arrow-down
                1
                ·
                edit-2
                15 hours ago

                exactly, but are people using it outside of proprietary apps like whatsapp? not really that much.

                no use in being open if in practice its still controlled by monopolistic corporations.

                i could use chrome or android as an example too. are there people using custom roms or forks and exercising their openness? yeah, but not that much either.

        • Zink@programming.dev
          link
          fedilink
          arrow-up
          17
          ·
          1 day ago

          Bitwarden has been working great with me as sits transition to passkeys, even big corporate ones.

          But yeah in practice, google and facebook are going to probably dominate because they are the easy + free option.

          • lime!@feddit.nu
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            4
            ·
            edit-2
            1 day ago

            thus rendering them redundant, because their strength is being bound to a single physical device. if they’re portable, they’re as good as asymmetric key pairs.

            • 4am@lemmy.zip
              link
              fedilink
              arrow-up
              8
              ·
              1 day ago

              Their strength is being half a cryptographic key, not that they’re device bound.

              That was a “requirement” that big tech wanted, to force you to be dependent on TPM storage, so you’d be forced to use a Trusted™ device and OS. It was made optional after pushback from basically everyone else.

              Password managers support Passkeys now. Bitwarden and KeePassX among others.

              As long as I trust that my password manager is secure, and as long as I use a strong master password or (better) have a hardware key to unlock it, it is way more secure than a password, and I can still install Linux without losing my logins.

          • ☂️-@lemmy.ml
            link
            fedilink
            arrow-up
            2
            ·
            1 day ago

            i’m assuming most people will use the default, which will probably be google lock in anyway.

      • Kaiserschmarrn@feddit.org
        link
        fedilink
        arrow-up
        9
        ·
        1 day ago

        bound to a single device

        Bitwarden let’s you sync your passkeys between devices. And you can also unlock your vault with one stored on a physical security key.

      • BeeegScaaawyCripple@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        23 hours ago

        i refuse to give my phone my thumbprint or do a face unlock. i’m not sure if it’s still collecting a biometric bullshit on my face, but i have not done it myself. I’m a luddite here and i insist on it so no one (especially no one trying to violate the united states 4th amendment) can get into my phone without my permission or hacking into it.

        • humorlessrepost@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          20 hours ago

          i refuse to give my phone my thumbprint or do a face unlock. i’m not sure if it’s still collecting a biometric bullshit on my face, but i have not done it myself.

          Then get a Yubikey. Replace “something you are” with “something you have”. It’s not ideal to have two somethings you have as your two factors, but a password to get into the computer to get to the passkey adds an extra layer that makes me comfortable with it.

          I’m a luddite here and i insist on it so no one (especially no one trying to violate the united states 4th amendment) can get into my phone without my permission or hacking into it.

          In the context of this discussion, it’s one of two factors. But I agree with you when it’s the only factor.

    • nearhat@lemmy.zip
      link
      fedilink
      arrow-up
      5
      arrow-down
      2
      ·
      edit-2
      1 day ago

      Ooh-la-la, someone’s gonna get laid in college.

      Edit: This is a joking reference from a Rick and Morty episode (S02E06).

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        You forgot, you descended into the lemmy-verse powering your car where the concept of Rick and Morty humor is not appreciated and often not tolerated.

        ;)

        WUBBU-LUBBA-DUB-DUB!!!

      • ☂️-@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        1 day ago

        i don’t get what this has to do with college, or getting laid at all but sure.

        • nearhat@lemmy.zip
          link
          fedilink
          arrow-up
          2
          ·
          1 day ago

          Oh, I’m sorry. It’s a reference to a Rick and Morty episode. I thought that’s what you were referring to.