this post was submitted on 09 Apr 2024
503 points (92.7% liked)

Technology

59207 readers
3307 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 
  • Big Tech has implemented passkeys in a way that locks users into their platforms rather than providing universal security
  • Passkeys were developed to replace passwords for better account security, but their rollout by Apple and Google has limited their potential
  • Proton Pass offers passkeys that are universal, easy to use, and available to everyone for improved online security and privacy.
you are viewing a single comment's thread
view the rest of the comments
[–] CriticalMiss@lemmy.world 50 points 7 months ago (3 children)

When vaultwarden supports this I’ll play ball. If I don’t have control over my authentication methods, then they aren’t my authentication methods.

[–] cooopsspace@infosec.pub 8 points 7 months ago* (last edited 7 months ago) (3 children)

Do you really think it's a good idea to store your password, TOTP and pass key in one place?

[–] hydration9806@lemmy.ml 14 points 7 months ago (1 children)

Yes, as long as that place is only accessible by a physical passkey (such as a Yubikey). The risk is miniscule and the convenience is 100% worth it.

[–] cooopsspace@infosec.pub 2 points 7 months ago

I'm actually not sold that I should be putting all my keys in a single password manager like Bitwarden.

[–] DreamlandLividity@lemmy.world 3 points 7 months ago (1 children)

To my bank? No. To a Lemmy account? Yep.

[–] Reddfugee42@lemmy.world 4 points 7 months ago (1 children)

Treating social media accounts as irrelevant is fine as long as none of your real life friends associate with you on the same platform. Once that's the case, scammers can take over your platform and send messages to your friends telling them you're stuck and need money or other sorts of things that sound ridiculous but work all the time.

[–] DreamlandLividity@lemmy.world 2 points 7 months ago

I am not treating them as irrelevant, hence a password manager. But I am not treating it as fort knox. Most of my real-life friends probably don't even go that far.

[–] EngineerGaming@feddit.nl 1 points 7 months ago

I personally settled on having TOTP in the same application but in a different database.

[–] ikidd@lemmy.world 4 points 7 months ago (1 children)

Bitwarden does, not sure about the self-hosted version.

[–] dantheclamman@lemmy.world 2 points 7 months ago

Still waiting for the mobile app. Maybe the firefox addon would work, but would prefer the app

[–] bitwolf@lemmy.one 3 points 7 months ago

Vaultwarden has supported pass keys for a while. The client app does all the hard work in this pattern.