veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

202
active users

#passkeys

11 posts8 participants0 posts today
betzerra<p>Has anyone experienced this error when using <a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a> at <a href="https://mastodon.social/tags/apple" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apple</span></a>? Password login works just fine. </p><p>cc <span class="h-card" translate="no"><a href="https://iosdev.space/@sanguish" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>sanguish</span></a></span> <span class="h-card" translate="no"><a href="https://hachyderm.io/@rmondello" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rmondello</span></a></span></p>
Auth Updates Bot<p>Add Harvard (#50)</p><p><a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a></p><p><a href="https://github.com/2factorauth/passkeys/commit/5a7a88766ae8332b72590d8f14ac53a13d767d95" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/2factorauth/passkey</span><span class="invisible">s/commit/5a7a88766ae8332b72590d8f14ac53a13d767d95</span></a></p>
Auth Updates Bot<p>Add Duke University's passwordless authentication (#47)</p><p><a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a></p><p><a href="https://github.com/2factorauth/passkeys/commit/6eeb3954781fc237120c6df4c80e731e695ec57c" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/2factorauth/passkey</span><span class="invisible">s/commit/6eeb3954781fc237120c6df4c80e731e695ec57c</span></a></p>
Erklärbär<p><a href="https://mastodon.social/tags/Token2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Token2</span></a> in CH is offering very good <a href="https://mastodon.social/tags/fido" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fido</span></a> keys with much more storage, for example, e.g. for <a href="https://mastodon.social/tags/passkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>passkeys</span></a>, and good prices.<br>A good alternative for American-based <a href="https://mastodon.social/tags/yubikeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>yubikeys</span></a> .</p>
Replied in thread

@maexchen1 @scuba_zeus @vowe Stimme ich voll zu. Mich nervt mittlerweile auch das sämtliche banken bei denen ich bin eine App benötigen für den Login. Ich mein, warum eigentlich? Ich will keine Banking App auf dem Handy. Wenn der normale Login unsicher ist, dann bietet halt #Passkeys an oder die Unterstützung von #yubikey. Das sind gesetzte gesicherte Standards, muss doch nicht jeder seine eigene App Entwickeln die benötigt wird zum Banking. Als Option gut und schön, aber doch nicht als Pflicht.

Replied in thread

@lsanoj Absolut!

Nicht zu vergessen: Das endlose Warten auf die Email oder SMS... Oder noch schlimmer, wenn man sich temporär auf einem Gerät anmelden möchte, welches einem nicht gehört. Good luck mit dem Abtippen des Links :D - dann ist dieser schon abgelaufen.

Email an sich ist super - Provider-unabhängige Kommunikation (was ja bei Messaging komplett schief geht: iMessage, Whatsapp, Signal, Messenger etc.)

Aber für einen Login-Prozess? Wenn passwordless, dann bitte richtig, mit #Passkeys.

I'm really wondering if syncable passkeys will turn out to be a mistake in the end.

For now it's a big improvement for almost everybody for now. But I'm wondering it's a question of time until the attackers catch up and figure out how to extract them, and then we're back where we started?

I love passkeys, but I'm really vary of storing all my eggs in one basket but everyone and their cousin is adding syncable passkey support to the password manager which makes the UX of keeping things separate really annoying.

And since the introduction of native webauthn support and then passkeys I have lost the ability to use the SEP as a non-syncable storage github.com/github/SoftU2F

I really liked how the keymaterial was locked into the SEP and "impossible" to export. But it was accessible with a simple TouchID.

While Apple does a lot of fancy stuff with SKP, it feels like that's so complex it can't be as secure.

Maybe something for @durumcrustulum and #scwpod ? The question being, does apple have some fancy crypto setup which makes extracting the passkeys uneconomical. How about the fact that I can unlock it with my N-pin passcode. Can I extract the keymaterial with that or only interact with it and get it to sign things for me?

Either way, I guess I won't be able to get rid of my Yubikey for a while still.

Software U2F authenticator for macOS. Contribute to github/SoftU2F development by creating an account on GitHub.
GitHubGitHub - github/SoftU2F: Software U2F authenticator for macOSSoftware U2F authenticator for macOS. Contribute to github/SoftU2F development by creating an account on GitHub.

I’ve been on a tear setting up hardware-bound #passkeys on my YubiKeys for services that support true passwordless.

It’s still regrettably rare, but Google, Microsoft, and Yahoo all support it, which does cover most people’s email.

My password manager has never done me wrong but it’s reassuring to know I can get into my most important accounts without it.

Bonus points to Microsoft for letting you completely remove your password from your account. You can’t phish something that doesn’t exist.