jviide.iki.fi

@jviide.iki.fi

cybersecurity charlatan ⋅ quadratic blowhard

there is essentially no downside to passkeys that are not also a downside to strong passwords, and a _lot_ of upsides.

So basically a) phishing is really bad b) email is very bad and SMS is worse c) public key cryptography is really good d) 2FA methods is an active insult to our collective intelligence e) 2FA is fragile and relies on external infra f) SSO == single point of failure g) SSO is not very single

Giovanni Campagna@gcampax.com · last wk.

To this day, I still don't understand what problems passkeys are trying to solve. Consumers just want to use one password for everything - thats been known forever. In enterprise, the answer is SSO via OIDC. Simple, secure, requires only one password, can enforce 2FA, ties to your OS.