• @Spotlight7573
    link
    English
    1084 months ago

    With a breach of this size, I think we’re officially at the point where the data about enough people is out there and knowledge based questions for security should be considered unsafe. We need to come up with different authentication methods.

      • 0^2
        link
        fedilink
        English
        94 months ago

        You get a private key! And you get a private key! And you get a private key!

        • @Nurgus
          link
          English
          54 months ago

          Indian accent: Hello, this is Microsoft support. Your private key is being hacked and you need to give it to us immediately for safe keeping.

          WCGW?

    • @[email protected]
      link
      fedilink
      English
      294 months ago

      We have different authentication methods. The hard bit is persuading people to use them.

      • @Spotlight7573
        link
        English
        23 months ago

        Before people can be persuaded to use them, we have to persuade or force the companies and sites to support them.

      • @ag10n
        link
        English
        10
        edit-2
        4 months ago

        Tying a password to a browser or device isn’t going to make it any easier. Use a password manager and set unique string passwords for everything. If the app supports it, use FIDO physical keys instead of Passkeys

        • @[email protected]
          link
          fedilink
          English
          84 months ago

          Even better would be to use certificates instead of passwords. What if every website gave you a certificate signed by them, and you store that in your password manager automatically.

          Maybe that’s what passkeys are… Haven’t read up on them at all.

          • @Spotlight7573
            link
            English
            64 months ago

            Basically with passkeys you have a public/private key pair that is generated for each account/each site and stored somewhere on your end somehow (on a hardware device, in a password manager, etc). When setting it up with the site you give your public key to the site so that they can recognize you in the future. When you want to prove that it’s you, the website sends you a unique challenge message and asks you to sign it (a unique message to prevent replay attacks). There’s some extra stuff in the spec regarding how the keys are stored or how the user is verified on the client side (such as having both access to the key and some kind of presence test or knowledge/biometric factor) but for the most part it’s like certificates but easier.

          • @Passerby6497
            link
            English
            14 months ago

            I really wish SQRL had taken off. It’s a lot like pass keys, but it used a central certificate to mint per-site certificates (along with per user per site certs if memory serves) and had proper methods of rolling it in and rotating the keys assigned to your account.

        • @QuarterSwede
          link
          English
          44 months ago

          … passkeys basically do all this without you having to know how. Your device /is/ the physical key and /you/ are the secondary auth. It honestly doesn’t get any easier for the user.

          • @ag10n
            link
            English
            13 months ago

            What options are there for migrating passkeys to a new device? Easy to lock you into that iPhone and you must use their migration tool when you upgrade. Or I just carry it on my keychain, no vendor lock in.

            • @QuarterSwede
              link
              English
              1
              edit-2
              3 months ago

              3rd party password managers are already adding passkey support. Passkeys isn’t an Apple only security technology. FIDO has its place but passkeys is the future for most people like it or not.

              • @ag10n
                link
                English
                -13 months ago

                Do I need a subscription service for this passkey supported password manager? Or I can just buy a hardware key that can be used on my phone or any device, password manager supported or not. Seems like the freedom and portability of a physical key, like a key to your home or car makes a ton of sense.

                Passkeys are based on and supported by the FIDO alliance.

                https://fidoalliance.org/passkeys/

                • @QuarterSwede
                  link
                  English
                  03 months ago

                  You don’t need a subscription as you well know since you know what they’re based on. And I meant FIDO physical keys as you were alluding to. Why would I ever want another device to use with a device that already has biometric auth? That last a barrier of entry that’s too high for most people.

      • fmstratOP
        link
        fedilink
        English
        54 months ago

        Until you realize Apple allows the iPhone to airdrop them. Ugh.

      • Scott
        link
        fedilink
        English
        64 months ago

        I want a stranger to grab my ass sometime

      • The Pantser
        link
        English
        24 months ago

        But I enjoy a booty grabbing.

    • @NotMyOldRedditName
      link
      English
      1
      edit-2
      4 months ago

      Start using Yubikeys and telling companies that don’t support them to support them.