• [object Object]@lemmy.ca
      link
      fedilink
      arrow-up
      28
      arrow-down
      6
      ·
      7 months ago

      Passkeys are okay, but your browser and OS want you to use them because you can’t just take a passkey to another platform, you have to create a new one, and it’s a pain in the ass.

      It’s a lock-in gimmick latching on to a real useful solution.

      • ricecake@sh.itjust.works
        link
        fedilink
        arrow-up
        3
        ·
        7 months ago

        My passkeys are tied to my phone, which I use via the browser and OS. I keep them in my password manager running on the phone. My password manager supports the open spec for securely migrating credentials between vendors.

        It may be difficult to believe but they want you to use them because they’re legitimately significantly better.

        Users are silly. They blame Microsoft for bad passwords. They blame Google for forgotten passwords. They blame Facebook when they click on a phishing link. They blame apple when apple “lets” someone who they gave their password to see their pictures. They blame apple when they don’t let the user in just because they forgot their password and every recovery mechanism.

        Everyone involved has a significant issue with passwords because they cost them user satisfaction, credibility, or money directly. The reason cross vendor transfer has been slow is because everyone wants to be the leader, since if everyone follows your lead you get to make it work better with your stuff.

      • Psychodelic@lemmy.world
        link
        fedilink
        arrow-up
        2
        ·
        7 months ago

        Ok that makes a lot of sense. It definitely seems like it’s more for them than it is for the user’s “convenience”

    • voidsignal@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      7 months ago

      Passkeys are fine. It’s just MTLS but by marketers (if by passcode you mean passkeys. otherwise, what’s a passcode?)