• Sign in
  • Sign up
Elektrine
EN
Log in Register
Modes
Overview Chat Timeline Communities Gallery Lists Friends Email Vault DNS VPN
Back to Timeline !programmer_humor @Jesus_666
In reply to 6 earlier posts
@bdjegifjdvw@lemmy.world on lemmy.world Open parent
I love password based login
Open parent Original URL
1344
0
231
@Assassassin@lemmy.dbzer0.com on lemmy.dbzer0.com Open parent
Just let me use passkeys at this point. The way that people typically use passwords is less secure anyway, why not just make it as simple as possible?
Open parent Original URL
31
0
12
@bleistift2@sopuli.xyz on sopuli.xyz Open parent
I forget. Are passkeys the access method that prevents you from logging in ever again if you lose access to a device?
Open parent Original URL
16
0
9
@Assassassin@lemmy.dbzer0.com on lemmy.dbzer0.com Open parent
Typically, no. You're thinking of TOTP/Authenticator based 2FA. Those still come with backup codes in case you break the phone that has the TOTP codes warehoused. I always recommend keeping those backup codes saved in the notes of whatever password manager you're hopefully using. Passkeys are essentially just one half of a cryptographic key pair (like what you'd use for authenticating SSH without passwords). These allow you to authenticate once using password + 2FA, then use the generated passkey for future sessions. Since these are much more complex than passwords and remove the need to actually remember anything, they are significantly more secure. There are also some other features that I'm forgetting, and that may not be a perfectly accurate description, but I think you can get the gist.
Open parent Original URL
17
0
5
@Jesus_666@lemmy.world on lemmy.world Open parent
Passkeys are supposed to be bound to one device and protected by that device's OS's secure enclave. If you have a second device you're supposed to create a second passkey. That's why many sites will flat out refuse to let you create a passkey with a desktop browser since a PC-stored passkey doesn't fit the security model.
Open parent Original URL
9
0
3
@zea_64@lemmy.blahaj.zone on lemmy.blahaj.zone Open parent
Websites should not get to dictate *my* security model. I'll accept annoying me about being less secure because I get that people are dumb, but you've gotta choose somehow! Also, any passkey is safer than a password, so that's still BS.
Open parent Original URL
4
0
1
3
Jesus_666 in !programmer_humor
@Jesus_666@lemmy.world · Mar 13
The logic behind it is that a smartphone-bound passkey represents two factors of authentication: what you have (the phone) and who you are (the fingerprint used to unlock the phone’s passkey store). Anything on a PC is easily copied and can only ever be safely assumed to represent one factor: what you know (the password to unlock your password manager). Thus the benefit of getting a two-factor authentication in one convenient step falls away. Of course it’s still super annoying, especially if you don’t really trust your smartphone OS vendor and use a portable password manager already.
View on lemmy.world
3
0
0
Sign in to interact

Loading comments...

About Community

programmer_humor
Programmer Humor
!programmer_humor@programming.dev

Welcome to Programmer Humor!

This is a place where you can post jokes, memes, humor, etc. related to programming!

For sharing awful code theres also Programming Horror.

Rules
  • Keep content in english
  • No advertisements
  • Posts must be related to programming or programmer topics
31013
Members
2241
Posts
Created: June 12, 2023
View All Posts
313k7r1n3

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • VPN Policy

Email Settings

IMAP: mail.elektrine.com:993

POP3: pop3.elektrine.com:995

SMTP: mail.elektrine.com:465

SSL/TLS required

Support

  • support@elektrine.com
  • Report Security Issue

Connect

Tor Hidden Service

khav7sdajxu6om3arvglevskg2vwuy7luyjcwfwg6xnkd7qtskr2vhad.onion
© 2026 Elektrine. All rights reserved. • Server: 05:44:33 UTC