Post B5f6C2l98b7kdzyMVM by joat@mastodon.scot
 (DIR) More posts by joat@mastodon.scot
 (DIR) Post #B5eZuQeAOBUaz4GTE8 by abucci@buc.ci
       0 likes, 0 repeats
       
       The typical webapp login process for me is anywhere from 5 to 7 steps, and I'd say I give up about 5-10% of the time after the 2nd CAPTCHA. I can't imagine this is good for anybody, and it almost surely does not reduce abuse either. Just a swirling dark pattern feeding on itself. Everyone likes to ape post-9/11 airport "security" for some reason.#tech #dev #SecurityTheater #DarkPatterns #UI #UX #security
       
 (DIR) Post #B5eacLwlE1KD9GuGky by randomgeek@masto.hackers.town
       0 likes, 0 repeats
       
       @abucci @hipsterelectron my new nemesis: sites that default to "use your passkey" and I'm on a fresh OS install or just never decided to make a passkey for that site.
       
 (DIR) Post #B5eacMDQE4eVywhZj6 by abucci@buc.ci
       0 likes, 0 repeats
       
       @randomgeek@masto.hackers.town @hipsterelectron@circumstances.run Putting aside whether or not passkeys are a good idea, such patterns make me suspicious. That's a nudge: they make the usual login flow painful, and make the passkey flow as easy as possible, because the latter is what they prefer you do. I inevitably put my guard up whenever I notice a nudge, and start asking questions about why I'm being coaxed down this particular flow.
       
 (DIR) Post #B5f6C1OQDbLuPEKhRg by troublewithwords@wandering.shop
       0 likes, 0 repeats
       
       @abucci @randomgeek @hipsterelectron The very first (and only) passkey I've experienced was "forced" on me through a dark pattern that tricked me to unintentionally click on a button. With that as my first experience, I'm forever on team No Passkey.  (Also no security expert has been able to explain them in fewer than 5,000 words, which make me assume most implementations are messed up somehow.)
       
 (DIR) Post #B5f6C1iH1nEROncYO8 by andrew@ottawa.place
       0 likes, 0 repeats
       
       @troublewithwords @abucci @randomgeek @hipsterelectron if you’re interested, I’m happy to put together a shorter explanation on why they’re actually great? And also why so many sites are trying to convince users to switch.
       
 (DIR) Post #B5f6C1tyKIabz55tce by troublewithwords@wandering.shop
       0 likes, 0 repeats
       
       @andrew @abucci @randomgeek @hipsterelectron No, I'm good. Seriously. No need for you to spend time on it.
       
 (DIR) Post #B5f6C25fcnwmZMZErA by mdm@mcnamarii.town
       0 likes, 0 repeats
       
       @troublewithwords @andrew @abucci @randomgeek @hipsterelectron I feel ya.  If someone could explain to me why they're great in _500_ words or less, I'd love that.(I personally use passkeys, but with a Yubikey.)
       
 (DIR) Post #B5f6C2H0wd1N8XsIXQ by joat@mastodon.scot
       0 likes, 0 repeats
       
       @mdm @troublewithwords @andrew @abucci @randomgeek @hipsterelectron I'll gloss over many details and have a go: they use the same basic techniques that are used to verify that websites really are who they claim to be, and critically the "secret" that identifies you is chosen at random by the hardware token or the computer, unlike a password which is chosen by users (who often choose weak secrets or reuse secrets between websites). There are other advantages but that's the gist.
       
 (DIR) Post #B5f6C2XfwgLfyDfbVY by ohir@vivaldi.net
       0 likes, 0 repeats
       
       @joat >  chosen at random by the hardware token or the computerThus it can not be trained into fingers and "for the convenience" of such secret user it is made easily availableby irrefutable and unchangeable but forgeable biometric traits.  > unlike a password which is chosen by usersThis can be put into a muscle memory, but is hard to guard against compromised OS.A hardware key with its own pinpad allowing for enough entropy password to unlock secrets inside is a good second factor.  Anything that keeps attestation for someone's identitity tied to unchangeable traits is a scam.Neither such device should be used alone without a second factor.The G "passkeys" is a big lie user security wise.  My $0.02@mdm @troublewithwords @andrew @abucci @randomgeek @hipsterelectron
       
 (DIR) Post #B5f6C2l98b7kdzyMVM by joat@mastodon.scot
       0 likes, 0 repeats
       
       @ohir @mdm @troublewithwords @andrew @abucci @randomgeek @hipsterelectron your points are well taken but the task was to explain why they were better than passwords in 500 words or less, not that they were *good*. 😀 Everything is a compromise.
       
 (DIR) Post #B5f6C2uMaKUr6aHis4 by ohir@vivaldi.net
       0 likes, 0 repeats
       
       @joat > 500 words or lessUh. Yeah, I should tap into the whole thread from the top not the bottom, my bad :))Physical key storages/authenticators (like fido) with pin-pads are better than passwords, passwords are better than anything biometric (that should never be used).  The G "passkeys" are the abomination.@mdm @troublewithwords @andrew @abucci @randomgeek @hipsterelectron
       
 (DIR) Post #B5f6C37pmFGvmMaTrs by abucci@buc.ci
       0 likes, 0 repeats
       
       @ohir@vivaldi.net @joat@mastodon.scot @mdm@mcnamarii.town @troublewithwords@wandering.shop @andrew@ottawa.place @randomgeek@masto.hackers.town @hipsterelectron@circumstances.run From my OP:Putting aside whether or not passkeys are a good ideaY'all are doing the thing I explicitly wanted to avoid. Please untag me.
       
 (DIR) Post #B5fFr4wIpvzCriphDc by mdm@mcnamarii.town
       0 likes, 0 repeats
       
       @abucci @ohir @joat @troublewithwords @andrew @randomgeek @hipsterelectron If anyone needs to mute this convo, click the pacman menu and choose "Mute Conversation":
       
 (DIR) Post #B5fFr5A80X2rYbIjlg by abucci@buc.ci
       0 likes, 0 repeats
       
       @mdm@mcnamarii.town Yes, I know how to mute a thread. It's fairly annoying to be condescended to while being given homework that suggests my request to be untagged will not be respected. I'll give you the benefit of the doubt and assume you didn't intend to serve up a 💩 sandwich.@ohir@vivaldi.net @joat@mastodon.scot @troublewithwords@wandering.shop @andrew@ottawa.place @randomgeek@masto.hackers.town @hipsterelectron@circumstances.run