this post was submitted on 09 Apr 2024
503 points (92.7% liked)

Technology

59589 readers
2936 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 
  • Big Tech has implemented passkeys in a way that locks users into their platforms rather than providing universal security
  • Passkeys were developed to replace passwords for better account security, but their rollout by Apple and Google has limited their potential
  • Proton Pass offers passkeys that are universal, easy to use, and available to everyone for improved online security and privacy.
you are viewing a single comment's thread
view the rest of the comments
[–] Dark_Arc@social.packetloss.gg 10 points 7 months ago* (last edited 7 months ago) (1 children)

That is not the takeaway here.

The takeaway is Passkeys are great technology but as implemented by Google, Microsoft, and Apple fall short of what they could be.

This isn't some "owned by the billionaire class". It's an open standard that's why Bitwarden and Proton both have implementations. Big tech of course provided implementations that are not as portable as possible, that's all that's going on here.

There's really not some big conspiracy to kill kittens or whatever. Passkeys are far more secure (and for most people far more usable) than passwords.

[–] umbrella@lemmy.ml 0 points 7 months ago* (last edited 7 months ago) (1 children)

The takeaway is Passkeys are great technology but as implemented by Google, Microsoft, and Apple fall short of what they could be.

then get them implemented by someone else useably. that open authentication login garbage they pushed years ago was also supposed to be an open standard, but you can only use it if you lock yourself in to facebook/google to this day. i still have to use a different password for each damn website still.

id like to see its opennes at work in the real world, in practice, first.

[–] Dark_Arc@social.packetloss.gg 5 points 7 months ago* (last edited 7 months ago) (1 children)

Proton, Bitwarden, 1Password, Yubico (via the Yubikey), and others (including big tech) already have their own independent implementations(?)

Even Keypass has at least a partial implementation https://github.com/keepassxreboot/keepassxc/pull/8825

[–] umbrella@lemmy.ml 2 points 7 months ago* (last edited 7 months ago) (2 children)

i'm sure they do, but can i login to most websites using them?

99/100 i get the option to use facebook, google or just bite the bullet and make an account. i'm talking about this by the way:

[–] EncryptKeeper@lemmy.world 6 points 7 months ago (1 children)

Yes. Any website that has implemented passkey authentication can be logged into by any Passkey provider. There are no websites that “Only accept Apple passkeys”

[–] Dark_Arc@social.packetloss.gg 4 points 7 months ago* (last edited 7 months ago)

I think you better understood their question; thanks for jumping in.

[–] Dark_Arc@social.packetloss.gg 1 points 7 months ago* (last edited 7 months ago)

It will get there... https://passkeys.directory/ https://passkeys.2fa.directory/us/

It's still relatively new technology.