Post B5QuXhyjA7wgtvRyNc by dchest@mastodon.social
(DIR) More posts by dchest@mastodon.social
(DIR) Post #B5KUoCBOrqOnSGoqzw by encthenet@flyovercountry.social
0 likes, 1 repeats
Just learned why I won't be using passkeys. Because it requires icloude keychain, and I definitely don't want apple having a copy of my passkeys.Yes, I know they're supposedly e2ee and everything, but also, allowing the passkey to transit devices actually means that it isn't really 2FA anymore, especially if you keep any password in the same keychain.It's pretty embarrassing how the security industry has managed to rebadge a not 2FA into 2FA.
(DIR) Post #B5KUoCPE2RSS99HtY0 by mwl@io.mwl.io
0 likes, 0 repeats
@encthenet If I can't print it on paper and store it in my safe deposit box, it's not "something I know."I'm certainly not going to authenticate with "something my computer knows."
(DIR) Post #B5QuXhyjA7wgtvRyNc by dchest@mastodon.social
0 likes, 0 repeats
@mwl @encthenet KeePassXC shows private keys for passkeys, so you can print them out 😀 It basically turns into ssh key management for websites. The keys are even in —BEGIN STUFF— format!