zlacker

[return to "A Tour of WebAuthn"]
1. _Alger+u81[view] [source] 2024-12-27 10:20:53
>>caust1+(OP)
Just like every other piece on passkeys it does not justify them, at all.

Passwords have problems, but less than putting all authentication secrets in a single basket or ecosystem is (which is what big tech fundamentally wants).

Passkeys are a solution to a manufactured problem, and keeps getting pushed because it is a useful big tech honey trap that solidifies their user's captivity in their ecosystems.

◧◩
2. pas+2e1[view] [source] 2024-12-27 12:04:29
>>_Alger+u81
Those are pretty strong claims.

KeePassXC has support. Many people use Vaultwarden. And so on.

Also, end users are already locked into Chrome and Safari (and Meta's webview and even worse fates).

Passkeys right now has upsides and downsides, like all technology.

I think they are both too complex/clunky on the data/spec/API side, and not complex enough on the UX/lifecycle side. But likely both will evolve based on the usage patterns that get solidified.

◧◩◪
3. eadmun+xi1[view] [source] 2024-12-27 13:11:19
>>pas+2e1
> KeePassXC has support. Many people use Vaultwarden. And so on.

It doesn’t matter if other authenticators could work if a relying party refuses to allow its users to use them.

> Also, end users are already locked into Chrome and Safari …

Not this end user; I am typing this in Firefox right now. Not coincidentally, WebAuthn is yet another bit of complexity making it slightly more difficult to implement a browser. From the perspective of the big tech companies, end users aren’t expected to write software, or to run anything the big tech companies haven vetted.

◧◩◪◨
4. lxgr+Mw1[view] [source] 2024-12-27 15:10:58
>>eadmun+xi1
> It doesn’t matter if other authenticators could work if a relying party refuses to allow its users to use them.

You keep repeating that, but that's not possible anymore, since both Apple and Google removed attestation from their respective passkey/WebAuthN implementations.

For details, see >>42522490 .

[go to top]