this post was submitted on 09 Apr 2024
503 points (92.7% liked)

Technology

59323 readers
4666 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 
  • Big Tech has implemented passkeys in a way that locks users into their platforms rather than providing universal security
  • Passkeys were developed to replace passwords for better account security, but their rollout by Apple and Google has limited their potential
  • Proton Pass offers passkeys that are universal, easy to use, and available to everyone for improved online security and privacy.
you are viewing a single comment's thread
view the rest of the comments
[–] laughterlaughter@lemmy.world 3 points 7 months ago (1 children)

No, sharing passkeys across services is way too risky. One service gets compromised, someone gets your passkey, and then they have access to all of your services. It's the same principle with regular passwords.

[–] Spotlight7573@lemmy.world 7 points 7 months ago (1 children)

Uh, each service only has access to your public key, not the private one that stays with you. It's less risky than a regular password.

Even with U2F hardware keys where the server-side stores the encrypted key (to allow for infinite sites to be used with a single hardware key), it's only decryptable on your key and thus isn't that useful for someone who has compromised a service.

[–] laughterlaughter@lemmy.world 4 points 7 months ago* (last edited 7 months ago) (1 children)

Thanks. I'm still learning about this "new" technology (which already is, what, eight years?)

[–] Natanael@slrpnk.net 1 points 7 months ago

It started with U2F which may be older?