Comment on Logging In Was Never Supposed to Be This Complicated
Maestro@fedia.io 5 days agoThat passkeys suck and that username + password + optional totp managed by a password manager is by far to easiest solution?
Comment on Logging In Was Never Supposed to Be This Complicated
Maestro@fedia.io 5 days agoThat passkeys suck and that username + password + optional totp managed by a password manager is by far to easiest solution?
panda_abyss@lemmy.ca 5 days ago
Yes! Passkeys don’t solve anything.
I just don’t see how you can do passkeys without still having passwords, so it’s nice that it can’t be phished, but your password still can!
If you did go pure passkeys, the second someone gets a new computer or phone, or switches phone type, or they have a house fire and their devices get destroyed, they’re kinda fucked.
Unless they have a password manager, which is a cheap point of failure that a lot of people don’t trust. But that doesn’t fix the above issues.
So where I’m at is keep your main passwords or password manager backup auth codes in a safe deposit box and just do whatever the fuck you find easier, and hope your house doesn’t burn down.
Kache@lemmy.zip 5 days ago
Passkeys are good at the fundamental level, but the practical implementation is lacking, despite their efforts.
IMO best way is /w a pw manager that’s also backed up, available, and synced everywhere you need it, but that’s a hurdle for most users.
I think the “intended way for normal ppl” is to set multiple keys, each on their trusted devices, like backup physical keys, but that’s kind of a pain to have for every service, too.