• DJKJuicy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    36
    arrow-down
    5
    ·
    3 days ago

    There is still nothing better than passwords.

    I don’t want my access to be tied to a specific device. Devices get lost, or break.

    I don’t want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.

    So current biometric security sucks. And passkeys suck.

    Also, though…passwords suck for all the reasons that we all already know.

    There has to be some better method that the owner can have full agency over, I just don’t know what. I don’t have the answers.

      • kellenoffdagrid@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 days ago

        That is a damn nice paper, thanks for sharing that! The comparison table is, if a little wacky-looking at first glance, a pretty great overview. I skimmed it for the abstract and conclusion but now I think it’s worth reading it in full.

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      2
      ·
      3 days ago

      Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.

      Passkeys may be a “step up” from password + TFA in terms of usability, but there’s such a variety of implementations and explanations of how those implementations “keep me secure” - I feel like any idiot who grabs my phone when I’m not looking and can follow my unlock finger smudges on the screen can use my pass keys… No thanks.

    • zerofk@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      This pretty much matches my feeling for the last 20 years or so. Passwords suck and are outdated technology. But every single alternative that has been developed over the years has sucked more, not less. They all have single-point-of-failure, vendor lock-in, assumptions about your “device”, etc.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      Hardware security keys is the other option. The FIDO2 ones are compatible with most sites using passkeys.