Hard pass. I will not use #passkeys and will tell my friends and family to do the same.

So long as attestation part of the WebAuthn spec, it allows companies to lock consumers into using specific passkey managers.

It's exactly like streaming subscriptions. Attestation sets up the dystopia of a paid 1Password account for your email passkey, a paid LastPass account for your utility account passkey, a paid Bitwarden account for your health insurance, etc.

#passwords

ncsc.gov.uk/blog-post/passkeys

@atoponce don’t several open source password managers support pass keys though? Or am I not understanding the subtle nature of the problem?

Follow

@CjMalone @feoh @atoponce
And another one that is tangentially related, a certification requirement that enforces users having less control: github.com/keepassxreboot/keep

@m0xee @atoponce Is this the same gigasperg spazzing out at the one password manager that allowed users to export passwords in plaintext because ERM CHUDDIE YOU CAN'T DO THAT USERS ARE DUMB STOP ENGAGING IN DOUBLE-PLUS UNGOOD THINK
Security whackos are wild.

@idiot @atoponce
Yep, it's the same person in both issues! One might think that passkeys solve old problems with fancy new cryptography, but in fact it's good olde public/private keypair authentication served under a different sauce, with vendor lock-in baked right in: phishing resistance is achieved solely through not being able to access the private key using normal means — otherwise the software you use to manage them won't pass the attestation. It's all marketing bullshit!

@m0xee @atoponce I guess it was obvious if I had read the details more carefully, I was just guessing based on his tone and vocabulary. Turns out I'm really good at noticing but only when it's bootlicking techbros.
Sign in to participate in the conversation
Librem Social

Librem Social is an opt-in public network. Messages are shared under Creative Commons BY-SA 4.0 license terms. Policy.

Stay safe. Please abide by our code of conduct.

(Source code)

image/svg+xml Librem Chat image/svg+xml