this post was submitted on 14 Feb 2024
262 points (88.8% liked)

Technology

59366 readers
3995 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Passkeys: how do they work? No, like, seriously. It’s clear that the industry is increasingly betting on passkeys as a replacement for passwords, a way to use the internet that is both more secure and more user-friendly. But for all that upside, it’s not always clear how we, the normal human users, are supposed to use passkeys. You’re telling me it’s just a thing... that lives on my phone? What if I lose my phone? What if you steal my phone?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 9 months ago (1 children)

There's no way for the average person to keep up with remembering unique, strong passwords for all the sites that require them.

Passphrases with a simple formula to make them unique for each site.

You just have to remember the formula, you get a strong unique password for each site.

Easy and safe, and doesn't tie you to a single point of failure like a specific device or a password manager.

Add two factor authentication on top (with multiple options, of course, otherwise you'll get locked out once you inevitably lose the second authentication method), and you can even safely use it from third party devices which you don't want to remember how to access your accounts.

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago)

Except if your “formula” is to make your passwords

Twit-(password)-ter

…it’ll be exceedingly obvious if someone were able to get your password from Twitter and then credential stuff at any other website. That’s not real security.

Also a password manager doesn’t have to be a single point of failure. First of all, they have like 3 or 4 points of failure before they actually lose anything, and you can always make an export or go back to a pen and paper password journal if you really want to to make an offline second point of failure.