Can anybody explain me why #passkeys are better for the security in comparison to 2FA?
https://www.corbado.com/blog/passkeys-vs-2fa-security
All of the arguments against "normal" 2FA can be made against passkeys if adoption stops..
[1/?]
@oscherler @m0xee no idea, I just dont like it when an imperfect solution is being replaced by another inperfect one and all praise it until the next best thing comes around the corner.
I guess I'm just getting old and dont believe in these things anymore.
@oscherler
I don't quite get your point. I don't expect my implementation to be technologically/cryptographically superior to what Apple/Google/MS can come up with — there is no need for it to be: centralised infrastructure, no matter how well defended will always remain an attractive target, my script — never will be, it's too unique and not worth the effort, this is purely practical standpoint🤷
@Anachron
@m0xee My point is that a lot of security experts agree that passkeys are better than passwords, immune to fishing, etc, yet you, obviously not a security expert, feel confident enough to suggest it’s all bullshit.
@Anachron
And passkeys… I don't get that either, to me this "just rely on someone's infrastructure and expect it to be secure and comfy" sounds like bullshit🤷