| ▲ | torstenvl 3 hours ago | ||||||||||||||||
Pro tip: if your substantive argument requires gaslighting people about the literal definitions of words, maybe you should take a step back. | |||||||||||||||||
| ▲ | bennetthilberg 2 hours ago | parent [-] | ||||||||||||||||
> gaslighting That is some serious semantic bleaching! I’m not disputing the fact that “secure” has different meanings in different contexts. My point is that when we talk about the “security” of authentication methods, we almost always are referring to its resistance to attacks, exploits, social engineering, etc. If you tell the average non-technical person that “passkeys are insecure,” they’ll think that it’s easier for (WLOG) Russian hackers to phish or bypass their way through some website’s passkey requirement. And to be clear, I don’t think it’s ridiculous to say that right now, the risk of lockouts outweighs the security benefits of passkeys. But this is a fixable problem. If it gets easier to securely recover or back up passkeys, I think we can reach what is more clearly a “best of both worlds” of security and reliability. | |||||||||||||||||
| |||||||||||||||||