| ▲ | crote 2 days ago |
| > at which point it’s no different to password syncing You still get the phishing resistance, though! |
|
| ▲ | TeMPOraL a day ago | parent | next [-] |
| Is the "phishing resistance" just inability to view and manage your own data? That's a bug, not a feature then. |
| |
|
| ▲ | choo-t 2 days ago | parent | prev [-] |
| Password managers prevent phishing as they check for the domain name before inputing the password. |
| |
| ▲ | jesseendahl 2 days ago | parent [-] | | Password managers do not architecturally, cryptographically make phishing impossible. Ultimately a user can still be tricked to copy/paste their passwords into fake websites, even when using a password manager. You could blame end-users for this behavior, but attackers don't care about blame. Ultimately, it doesn't matter who's at fault when there are massive phishing attacks happening at scale every single hour of every day. The only real solution to solve this problem for the entire internet is to make credentials architecturally, cryptographically unphishable by design. That's what passkeys give you. |
|