• 0 Posts
  • 47 Comments
Joined 2 years ago
cake
Cake day: June 22nd, 2023

help-circle

  • The only thing we know without a proof is that they might be doing it. We don’t have a proof they do it but we also don’t have any proof they are incapable of doing so. A reasonable course of action would be to take precautions against it while not condemning them either, until they are either proven actually guilty or actively unwilling to up their security, which would also strongly imply the former.

















  • It certainly feels dangerous if forced upon users not aware of the trade-offs. For people already accustomed to using hardware keys, it’s very much an improvement, as more services will support them too. The problem is in the awareness. On the other hand, people already treat regular passwords as throwaway data and expect services to just let them in, or even never log them out. In this scenario, maybe passkeys can still be an improvement: roughly just as much as enforcing using a password manager.