veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

272
active users

#passkeys

6 posts6 participants1 post today

Really looking forward to the .NET day 2025 in Zurich this Tuesday. I will be talking about: Modern Web Applications Require Modern Security

dotnetday.ch/speakers/damien-b

Security is so exciting at present with so many new problems to solve. Looking forward to chatting with everyone. Come say hello of you are there.

#openid #oauth #owasp #iam #identity #passkeys #mfa #openidconnect #devSecOps #eid #swiyu #mcpoauth #trust #sast #sbom .NET Day Switzerland

www.dotnetday.chDamien Bowden @ .NET Day Switzerland.NET Day - The community event in Switzerland

These can both be true:

  • Passkey deployment has been fraught with UX challenges, failures to advise users about threat model trade-offs, and vendor lock-in concerns

  • The ecosystem couldn't go much longer without the benefits of passkeys (reducing password reuse risk, mitigating infostealer harm, and deploying FIDO2 phishing resistance at scale)

@jik I have accidentally accepted a couple of #passkeys. I get it - it’s just normal PKI - but I need to figure out how to unwind those site logins where suddenly I’m in an unrecoverable zone if I screw up the backups.

Passkeys are shaping up to be a user-side failure akin to PGP. But credit to PGP: people very rarely accidentally PGP their messages.

Question for all the privacy/security smarties.

I was reading about those physical passkeys (like Yubico). My primary hangup is that a tiny USB stick can be easily lost/damaged. That seems like a huge risk.

What I’ve read about these passkeys seems ambiguous at best. Is there a strong argument for their use? If so, how does one backup a hardware passkey to mitigate the risk of loss/damage?

ISN is #rollingcode! It's temporary, a new code generates on every #carkey's #enginestart.
So, this code doesn't mean You forever access the vehicle's #carimmobiliser, seen🤔?

#HapaUjanjaTu, this rubbish makes You #mjanja for #passkeys from #EEPROM's data, do #lostkeys #ECUProgramming #ecurepair👇

5021.tips/ujanja/keyprogramming

👆☝️
#InshaAllah, may whatever nonsense make sense do #carkeyprogramming #smartkeyprogramming #immoff #programmingtips #5021tips #techtips #autoelectronics

Continued thread

TIL #Passkeys for Apple ID do NOT show in Passwords.app > Passkeys on macOS. There is also no way to remove a passkey in AppleID webUI. Or at least Apple support was not aware of any way.

Fun times.