this post was submitted on 16 Oct 2024
270 points (86.3% liked)

Technology

59377 readers
5811 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] azalty@jlai.lu 30 points 1 month ago (13 children)

I have never understood the goal of passkeys. Skipping 2FA seems like a security issue and storing passkeys in my password manager is like storing 2FA keys on it: the whole point is that I should check on 2 devices, and my phone is probably the most secure of them all.

[โ€“] imouto@lemmy.world 4 points 4 weeks ago

It's not skipping MFA cos some media can provide more than one factor.

E.g. YubiKey 5 (presence of the device) + PIN (knowledge of some credentials) = 2 factors

Or YubiKey Bio (presence of the device) + fingerprint (biological proof of ownership) = 2 factors

And actually unless you use one password manager database for passwords, another one for OTPs, and never unlock them together on the same machine, it's not MFA but 1FA. Cos if you have them all at one place, you can only provide one factor (knowledge of the manager password, unless you program an FPGA to simulate a write only store or something).

load more comments (12 replies)