• Katana314@lemmy.world
    link
    fedilink
    English
    arrow-up
    37
    ·
    3 days ago

    There’s been a lot of pain in the attempt to portray it as “Just click the passkey button, and that’s it! Your login is secured for life!”

    No - Buddy. It is secured for this one specific device that I have biometric authentication for. What about my computer? What about my other computer that isn’t on the same operating system? I have a password manager that stores these things, why didn’t you save to that when I registered? Why is it trying to take this shit from my Apple Keychain when it’s in Bitwarden?

    And, the next ultra-big step: How would a non-techie figure this shit out?

    • candybrie@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      1 day ago

      And, the next ultra-big step: How would a non-techie figure this shit out?

      They don’t have a computer, another computer with a different OS, or bitwarden.

    • I use both Bitwarden and Apple’s native Passwords.app and just save a passkey for each app. Usually you can name the passkey on the website/in the app as well.
      This is also the system I use when saving 2FA TOTP codes as well so I guess I’m used to it, but it makes good sense to me to have reduncancy in my password apps. Also I lock up *the apps themselves* with passkeys in the respective app for ease of use.
      :mastozany:

    • BorgDrone@lemmy.one
      link
      fedilink
      arrow-up
      6
      ·
      3 days ago

      No - Buddy. It is secured for this one specific device that I have biometric authentication for. What about my computer? What about my other computer that isn’t on the same operating system?

      Then use a Yubikey.

      • MDCCCLV@lemmy.ca
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        I tried a yubikey but most websites want you to use the pin for that which requires windows hello, and if you reset windows you lose that.

    • I Cast Fist@programming.dev
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      And, the next ultra-big step: How would a non-techie figure this shit out?

      They wouldn’t, because the people calling the shots in the tech world create UX with a focus on it sucking for everyone

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      2 days ago

      This was roughly the state of affairs before but the state of things have relented where software password managers are now allowed to serve the purpose.

      So if a hardened security guy wants to only use his dedicated hardware token with registering backups, that’s possible.

      If a layman wants to use Google password manager to just take care of it, that’s fine too.

      Also much in between, using a phone instead of a yubikey like, using an offline password manager, etc.