Jump in the discussion.

No email address required.

Passkeys sound fricking r-slurred, guess I shouldn't be surprised from the people who dreamt up 2FA.

Jump in the discussion.

No email address required.

yeah, for some reason gmail and amaxon kdep prompting me for my computer's microsoft pin. You can simply vlose the popup and login like normal butt its annoying

Jump in the discussion.

No email address required.

The guys in charge of gmail auth are geniuses. I made sure to deactivate 2FA so I'd only ever need my password and not be fricked if I was without my device but last time I was in the hospital they wouldn't let me log-in with my password because I had a different IP.

Jump in the discussion.

No email address required.

I'll one up you, I signed up for twitter with my work gmail, twitter automatically used my real name for my account and because I signed up via google (had no twitter password) I couldn't change it

Jump in the discussion.

No email address required.

The problem with passkeys is that it completely fricks the user's mental model of what's going on and what's safe.

What actually happened: your computer has a keystore it uses to authenticate you to remote services, and the browser makes you authenticate yourself to it before using the keystore to log you in.

What the user thinks happens: a website asks you for a password, so you enter your computer password and you've logged in.

Fake passkey prompts are going to utterly annihilate the boomers

Jump in the discussion.

No email address required.



Link copied to clipboard
Action successful!
Error, please refresh the page and try again.