• hemko@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    10 days ago

    What’s wrong with passkeys? I’m in love with passwordless sign-in with yubikey, so much easier and faster than password + totp

    • deegeese@sopuli.xyz
      link
      fedilink
      arrow-up
      1
      ·
      10 days ago

      It’s shitty user experience when forced to dig out my phone to authenticate myself to a site I barely give half a shit about.

      Like I wouldn’t even have an account if it wasn’t forced, and now you assholes want my phone too?

        • deegeese@sopuli.xyz
          link
          fedilink
          arrow-up
          1
          ·
          10 days ago

          Security for who exactly?

          If I don’t even want an account, it’s the “security” of the sites ad targeting data that IDGAF.

    • henfredemars@infosec.pub
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 days ago

      I don’t like how there isn’t a nice, cross-platform and secure way to sync my keys. Not all services allow multiple keys to exist at once.

      • Semperverus@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 days ago

        The syncing of keys allows for much greater attack surface.

        Its being worked on right now but the standard hasn’t been finalized yet.

        • Kusimulkku@lemm.ee
          link
          fedilink
          arrow-up
          1
          ·
          10 days ago

          Until exporting and syncing keys is properly implemented, passkeys can go kick rocks.