home.social

#autofill — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #autofill, aggregated by home.social.

  1. @ScottHelme "This is mostly a list of things passkeys were never claimed to solve":

    1. You skipped the "private key never leaves the device" lie. Note that this vuln: seclists.org/fulldisclosure/20 is unfixed (see todon.nl/@ErikvanStraten/11655).

    The alternative, having access to YOUR OWN private keys does not make #BigTech lock-in vendors (i.e. Google, Apple) happy: github.com/keepassxreboot/keep.

    Btw, also unfixed: iOS/iPadOS passkeys may be used without local auth under certain conditions: todon.nl/@ErikvanStraten/11565 (@timcappalli ).

    2. Nobody cares what is considered out of scope for ANY auth. solution, in particular if it they're not told about it. People want to know their risks w.r.t. account takeover and account lockout. We need a safer internet.

    3. "Passkeys are not magic": I don't see "what risks remain" in scotthelme.co.uk/passkeys-101- - which is why I objected.

    4. Passkeys "are a major improvement over passwords": that depends. If people use a password manager to create unique long random passwords (which they should), and use AutoFill, then the advantages and risks (attestation?) of using passkeys vs passwords are not clear and neither easily comparable.

    #Passkeys #AndroidPasskeysGone #ApplePasskeyRisks #Passkey #PasswordManager #AutoFill #Autonomy #BigTechIsEvil #MYprivateKeys #DumbPasswordRules

  2. @ScottHelme "This is mostly a list of things passkeys were never claimed to solve":

    1. You skipped the "private key never leaves the device" lie. Note that this vuln: seclists.org/fulldisclosure/20 is unfixed (see todon.nl/@ErikvanStraten/11655).

    The alternative, having access to YOUR OWN private keys does not make #BigTech lock-in vendors (i.e. Google, Apple) happy: github.com/keepassxreboot/keep.

    Btw, also unfixed: iOS/iPadOS passkeys may be used without local auth under certain conditions: todon.nl/@ErikvanStraten/11565 (@timcappalli ).

    2. Nobody cares what is considered out of scope for ANY auth. solution, in particular if it they're not told about it. People want to know their risks w.r.t. account takeover and account lockout. We need a safer internet.

    3. "Passkeys are not magic": I don't see "what risks remain" in scotthelme.co.uk/passkeys-101- - which is why I objected.

    4. Passkeys "are a major improvement over passwords": that depends. If people use a password manager to create unique long random passwords (which they should), and use AutoFill, then the advantages and risks (attestation?) of using passkeys vs passwords are not clear and neither easily comparable.

    #Passkeys #AndroidPasskeysGone #ApplePasskeyRisks #Passkey #PasswordManager #AutoFill #Autonomy #BigTechIsEvil #MYprivateKeys #DumbPasswordRules

  3. @ScottHelme "This is mostly a list of things passkeys were never claimed to solve":

    1. You skipped the "private key never leaves the device" lie. Note that this vuln: seclists.org/fulldisclosure/20 is unfixed (see todon.nl/@ErikvanStraten/11655).

    The alternative, having access to YOUR OWN private keys does not make #BigTech lock-in vendors (i.e. Google, Apple) happy: github.com/keepassxreboot/keep.

    Btw, also unfixed: iOS/iPadOS passkeys may be used without local auth under certain conditions: todon.nl/@ErikvanStraten/11565 (@timcappalli ).

    2. Nobody cares what is considered out of scope for ANY auth. solution, in particular if it they're not told about it. People want to know their risks w.r.t. account takeover and account lockout. We need a safer internet.

    3. "Passkeys are not magic": I don't see "what risks remain" in scotthelme.co.uk/passkeys-101- - which is why I objected.

    4. Passkeys "are a major improvement over passwords": that depends. If people use a password manager to create unique long random passwords (which they should), and use AutoFill, then the advantages and risks (attestation?) of using passkeys vs passwords are not clear and neither easily comparable.

    #Passkeys #AndroidPasskeysGone #ApplePasskeyRisks #Passkey #PasswordManager #AutoFill #Autonomy #BigTechIsEvil #MYprivateKeys #DumbPasswordRules

  4. @ScottHelme "This is mostly a list of things passkeys were never claimed to solve":

    1. You skipped the "private key never leaves the device" lie. Note that this vuln: seclists.org/fulldisclosure/20 is unfixed (see todon.nl/@ErikvanStraten/11655).

    The alternative, having access to YOUR OWN private keys does not make #BigTech lock-in vendors (i.e. Google, Apple) happy: github.com/keepassxreboot/keep.

    Btw, also unfixed: iOS/iPadOS passkeys may be used without local auth under certain conditions: todon.nl/@ErikvanStraten/11565 (@timcappalli ).

    2. Nobody cares what is considered out of scope for ANY auth. solution, in particular if it they're not told about it. People want to know their risks w.r.t. account takeover and account lockout. We need a safer internet.

    3. "Passkeys are not magic": I don't see "what risks remain" in scotthelme.co.uk/passkeys-101- - which is why I objected.

    4. Passkeys "are a major improvement over passwords": that depends. If people use a password manager to create unique long random passwords (which they should), and use AutoFill, then the advantages and risks (attestation?) of using passkeys vs passwords are not clear and neither easily comparable.

    #Passkeys #AndroidPasskeysGone #ApplePasskeyRisks #Passkey #PasswordManager #AutoFill #Autonomy #BigTechIsEvil #MYprivateKeys #DumbPasswordRules

  5. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX

  6. @Tutanota : rubbish.

    Two WEAK locks may be LESS pointless than one WEAK lock, but they're still pointless. Go read csoonline.com/article/4147134.

    U2F has been superseded by FIDO2 (hardware keys in WebAuthn mode) and Passkeys (example in Dutch: todon.nl/@ErikvanStraten/11628).

    Both WebAuthn methods have advantages and disadvantages.

    If you don't like them, use a trustworthy passwordmanager and:

    • Let it create a unique, random, as long as possible, pw per account

    • Make backups of the pw mngr database

    • Device compromise means "game over"

    • Use Autofill (easy in Android and iOS/iPadOS)

    • If Autofill does not automatically retrieve your credentials, it probably is a fake (phishing) website. Do read troyhunt.com/a-sneaky-phish-ju

    Please stop misinforming people.

    #WeakMFAsucks #Weak2FAsucks #FIDO2 #WebAuthn #Passkeys #AutoFill #KeePassium #KeePassDX

  7. @maaikees : unfortunately, no. If such a solution would exist, spammers and phisher-(wo)men would immediately start using it.

    Using an email provider with a good reputation *or* (evil) big tech is your best bet.

    Note: when switching email provider, first make a list of *all* websites where you have an account, either with the old email address as user-ID or another user-ID but where the old email address can be used for password resets.

    It's okay to create a new email address (using another provider and domain name), but do not close your old email account until it has been removed (or replaced by your new address) from all websites where it may be used to authenticate you.

    My advice: use a password manager (*). Apart from other advantages, if you record in it every site where you enter your email address, you'll have a nice overview of sites that know your email address.

    (*) Full list of tips:
    Dutch: security.nl/posting/912904

    English: see the list in todon.nl/@ErikvanStraten/11561

    #PasswordManager #AutoFill #PhishingPrevention #Phishing

  8. @maaikees : unfortunately, no. If such a solution would exist, spammers and phisher-(wo)men would immediately start using it.

    Using an email provider with a good reputation *or* (evil) big tech is your best bet.

    Note: when switching email provider, first make a list of *all* websites where you have an account, either with the old email address as user-ID or another user-ID but where the old email address can be used for password resets.

    It's okay to create a new email address (using another provider and domain name), but do not close your old email account until it has been removed (or replaced by your new address) from all websites where it may be used to authenticate you.

    My advice: use a password manager (*). Apart from other advantages, if you record in it every site where you enter your email address, you'll have a nice overview of sites that know your email address.

    (*) Full list of tips:
    Dutch: security.nl/posting/912904

    English: see the list in todon.nl/@ErikvanStraten/11561

    #PasswordManager #AutoFill #PhishingPrevention #Phishing

  9. Một tiện ích mở rộng Chrome đang được phát triển để tự động điền biểu mẫu Google và Microsoft. Ứng dụng này sẽ học các câu trả lời của người dùng và sử dụng AI để giải đáp các câu hỏi mở. Sẽ có phiên bản miễn phí và trả phí. Hiện tại, nhà phát triển đang thu thập email cho danh sách chờ.
    #TiệnÍchChrome #ĐiềnFormTựĐộng #AI #CôngNghệMới #ChromeExtension #AutoFill #AItools #SideProject

    reddit.com/r/SideProject/comme

  10. We have all accidentally typed a #password into a username field and had it stored by the #autofill of Chrome etc. to become visible by e.g. another user of your machine / session. How can it be that one cannot set it so that stupid behaviour is not possible? Can I set a #whitelist of autofill text that is allowed and block all others? Or do I have to block autofill completely for ever? #2Fa