Zum Inhalt der Seite gehen

Suche

Beiträge, die mit Passkeys getaggt sind


I genuinely forgot my phone pin for ~12 hours.

A pseudo-pattern, because #grapheneOS doesn't allow actual patterns on the basis they are less secure 🙃

Managed to shift the 2 starting numbers to one side. After ~60 brute-force attempts from this incorrect starting position, my intuition/desperation lead me to the correct start position -> success 👴

Super insecurity-inducing episode. (And what about accident induced memory loss? Dementia? Perhaps biometric #passkeys solve it all /s) #infosec


#1Password is a password manager so mostly it’s used to store your regular passwords. It gets installed as either a separate app or an extension loaded inside your browser. I only installed the browser extension. Your passwords and now your #passkeys are synchronized by encrypting them locally and sending the encrypted data to 1Password. When you install the same extension on another computer or mobile device you get your encrypted data back and (after entering your master password again) they are available on that device too. It’s slick. Definitely test it out!

#Yubikey is not really related, it’s more like a USB memory stick just for one-time passwords, certificates, and other advanced security uses. You might want to get one if you’re looking for that extra level of security, but honestly the number of web sites and applications that support Yubikey and security keys is small right now. Passkeys is going to definitely help power up their business, but most people won’t need one


Nerds everywhere, if you know your way around 2FA and a password manager, read up on passkeys and share the info with your friends. They will be asking you anyway. If you agree this is a BIG step forward, now is the time to evangelize and get in front of the FUD.

This is my "short form" version of #Passkeys explainer.

"Public key cryptography" - probably the easiest for people to understand and trust. SSL, SSH, PGP all use this.

"Device sync" - If you already use a password manager with sync feature, this is like that. If you prefer secrets kept on your device only, there will be solutions to that coming. #Yubikey is one that exists now.

"Biometrics" - Think of this as just like unlocking your PC, if you trust Apple to keep your bio info only on the device. If not, you can just use a PIN or PC unlock password.

"QR/BT" - This is how you use your phone to unlock something on another computer like at work/school/library/a friend's.

"What if I lose my device" - Keep a backup method or multiple devices.