• 0 Posts
  • 358 Comments
Joined 2 years ago
cake
Cake day: June 9th, 2023

help-circle

  • Nawor3565tosimpsonsshitposting@sh.itjust.worksGo on then
    link
    fedilink
    English
    arrow-up
    7
    ·
    21 days ago

    Sure, but if no one can afford to buy artificially inflated real meat prices, that’s a good reason to sell fake beef at a price where people can afford it… And THEN you start to increase the price of that too, but only once a Democrat is president so people can freak out like they did with egg prices







  • Dude if you think that someone might scrape your finger print from a random image post, recreate a physical model of it, hunt you down in real life, and steal your phone to unlock it… You probably should be seeking political asylum because you’re being hunted down by the Kremlin or a similar entity.

    My point being, unless you’re wanted by a governmental power, a photo with fingerprints is probably not a real risk. Gotta make a realistic threat model, otherwise there’s no way to tell what’s reasonable privacy considerations vs. paranoia.








  • Nawor3565toPieFed Meta@piefed.socialPasskeys in PieFed
    link
    fedilink
    English
    arrow-up
    7
    ·
    4 months ago

    Here’s the thing: you don’t necessarily need to use biometric data to store a passkey. That’s how the vast majority of current implementations do it, but it’s not required by the spec. Personally I store all my passkeys in Bitwarden, meaning I can lock them behind my master password with no bio data involved. It also means that my passkeys are platform non-specific and are stored on my own self-hosted Bitwarden instance instead of in some mega-corp’s cloud.

    As for SSH vs passkeys, AFAIK they’re both based on the same encryption but SSH keys are just super low level (the raw key in what’s essentially a text file) vs. the more abstracted passkey system that, in theory, is more user-friendly.




  • The problem is that brute-forcing passwords hasn’t been a thing for ages. It’s all about phishing and social engineering now, something passwords can’t protect against. It doesn’t seem like they’re pushing for pins as much as passkeys, which I much prefer using over other bandaid fixes like SMS 2FA (well, now that Firefox for Android properly supports using passkeys from Bitwarden. Before they fixed that, they were really obnoxious to use).