[Lex Computer & Tech Group/LCTG] A case against passkeys
Robert Primak
bobprimak at yahoo.com
Fri Jan 3 03:51:53 PST 2025
I know the main reason I don't use a password manager or passkeys is the lack of a single, universally applicable way to create and use them at various websites or for various login types.
Even if you choose to use a dongle like YubiKey or your own FIDO U2F USB key, there are still many competing and incompatible standards out there. And some options have undesirable privacy and security implications.
For example, I will not log in as Administrator and I will not use a Microsoft Cloud Account login to do banking or financial business. Yet, Microsoft offers no other way to use Passkeys. So much for added "security".
Wake me up when all of this is sorted out.
-- Bob Primak
On Thursday, January 2, 2025 at 08:47:42 PM EST, Peter Albin via LCTG <lctg at lists.toku.us> wrote:
Good article It highlights transferring one security issue for another Like many other technical “solutions “ the secret to acceptance is the user experience
Peter
On Jan 2, 2025, at 5:50 PM, Adam Broun via LCTG <lctg at lists.toku.us> wrote:
I know we’ve had some good discussions about Passkeys and their advantages. Here’s an article on some drawbacks. tl;dr - it’s not that they’re insecure, it’s that they are implemented in many different ways which makes using them more complicated than they should be.
| <passkey-1000x648.jpeg> |
|
| Passkey technology is elegant, but it’s most definitely not usable securityarstechnica.com |
|
===============================================
::The Lexington Computer and Technology Group Mailing List::
Reply goes to sender only; Reply All to send to list.
Send to the list: LCTG at lists.toku.us Message archives: http://lists.toku.us/pipermail/lctg-toku.us/
To subscribe: email lctg-subscribe at toku.us To unsubscribe: email lctg-unsubscribe at toku.us
Future and Past meeting information: http://LCTG.toku.us
List information: http://lists.toku.us/listinfo.cgi/lctg-toku.us
This message was sent to palbin24 at yahoo.com.
Set your list options: http://lists.toku.us/options.cgi/lctg-toku.us/palbin24@yahoo.com
===============================================
::The Lexington Computer and Technology Group Mailing List::
Reply goes to sender only; Reply All to send to list.
Send to the list: LCTG at lists.toku.us Message archives: http://lists.toku.us/pipermail/lctg-toku.us/
To subscribe: email lctg-subscribe at toku.us To unsubscribe: email lctg-unsubscribe at toku.us
Future and Past meeting information: http://LCTG.toku.us
List information: http://lists.toku.us/listinfo.cgi/lctg-toku.us
This message was sent to bobprimak at yahoo.com.
Set your list options: http://lists.toku.us/options.cgi/lctg-toku.us/bobprimak@yahoo.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.toku.us/pipermail/lctg-toku.us/attachments/20250103/a48ea37f/attachment.htm>
More information about the LCTG
mailing list