@Anachron@fosstodon.org
> I don't know anybody writing down 2FA passwords or codes
I do! And OTPs are generated by a script on a particular machine that I call over ssh — so those aren't stored on the same machine I'm logging in from😁
@oscherler
I don't quite get your point. I don't expect my implementation to be technologically/cryptographically superior to what Apple/Google/MS can come up with — there is no need for it to be: centralised infrastructure, no matter how well defended will always remain an attractive target, my script — never will be, it's too unique and not worth the effort, this is purely practical standpoint🤷
@Anachron@fosstodon.org
@m0xee My point is that a lot of security experts agree that passkeys are better than passwords, immune to fishing, etc, yet you, obviously not a security expert, feel confident enough to suggest it’s all bullshit.
@Anachron@fosstodon.org
And passkeys… I don't get that either, to me this "just rely on someone's infrastructure and expect it to be secure and comfy" sounds like bullshit🤷