| ▲ | 3RTB297 2 days ago | |||||||||||||||||||||||||||||||
My issue is that they're touted to the consumer as secure, and they're not really doing much more than a complex password. How do you generate a new key if you need one? Same process as a password reset. Does it prevent session stealers? Not at all. Its "benefit" is grandma can't read it to an attacker. OK, well can grandma click a link and have a session stealer bork her life instead? Yeah, and attackers know that and just shift methods. Session stealing isn't a sophisticated attack, and so all that's being done is shaving a cost on PW resets in the interest of shareholder value, at the cost of security theater and locking up your keys in a single domain that holds control over our access to everything. | ||||||||||||||||||||||||||||||||
| ▲ | zdp7 2 days ago | parent [-] | |||||||||||||||||||||||||||||||
There is security value. A passkey will not work anywhere except the actual website. Fake look a like sites can't get the credentials. Evidently they can trick you into authorizing their device. | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||