#passkey — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #passkey, aggregated by home.social.
-
Wie dumm ist eigentlich die #Passkey Lösung der #Telekom ?
Es ist nicht ordentlich #FIDO2 sondern muss auf #Google #Apple oder #Windowshello erfolgen. Mit einem #Yubikey #Token2 oder so funktioniert es nicht. Auch lässt sich nur eine (in Zahlen: 1!) APP oder Gerät für #2FA wie ein #Autenticator hinterlegen...
Und die #MagentaAI kann einem das nicht beantworten. Nach längerer Konversation bietet sie an mit dem Hinweis "Service Team" an den Support durchzustellen.
Das klappt natürlich auch nicht. Macht man das, fragt die #AI worum es geht. Ob Internet oder Mobilfunk...Das ist ein Konzern, zu dem #TSystems gehört? Geil!
-
«Insgesamt sei es „etwas besorgniserregend“, dass Menschen vermehrt Passkeys nutzen, ohne deren Funktionsweise zu verstehen.»
- Verständlich. Hatte vor Kurzem einer Kollegin geholfen wegen einem Zugang. Hatte gesehen, dass sie diesen mit dem Passkey geschützt hat und war mega beeindruckt. Hatte ihr das auch gesagt und sie so: «Was ist ein Passkey???»Studie zum Umgang mit #Passkeys: Nutzer wissen zu wenig Bescheid | Security https://www.heise.de/news/Studie-zum-Umgang-mit-Passkeys-Teilweise-gefaehrlicher-als-Passwoerter-11413954.html #Passkey
-
Study on handling passkeys: partly more dangerous than passwords
Passkeys are designed to replace passwords and are considered more secure, but a US research team found major issues in their use.
-
Studie zum Umgang mit Passkeys: Teilweise gefährlicher als Passwörter
Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. Beim Umgang damit gibt es aber teils erhebliche Probleme, hat ein US-Forschungsteam ermittelt.
-
Many new features and numerous breaking changes in .NET 11.0 Preview 7
The seventh preview again brings a language extension for C#, improved compression APIs, and new features for Blazor.
-
Nochmals viele Neuerungen und zahlreiche Breaking Changes in .NET 11.0 Preview 7
Die siebte Preview bringt abermals eine Spracherweiterung für C#, verbesserte Komprimierungs-APIs und neue Features für Blazor.
-
“Malware installed on a device running #macOS, #iOS, and #Android, for instance, has no ability to defeat this isolation unless the OS itself is compromised […]. The lone exception is #Windows. […] Windows apps generally run with all the privileges of the user, [and] it doesn’t prevent unsandboxed apps such as #malware from accessing the data of a sandboxed app.”
-
Passkeys in Practice – Part 2: Registration and Authentication
The exact processes for registration and login with passkeys are complex. Knowing them allows for secure and specification-compliant implementation.
#IdentityManagement #Developer #IT #Passkey #Security #Softwareentwicklung #news
-
Passkeys in der Praxis – Teil 2: Registrierung und Authentifizierung
Die exakten Abläufe bei Registrierung und Anmeldung per Passkey sind komplex. Wer sie kennt, kann das Verfahren sicher und spezifikationsgemäß implementieren.
#IdentityManagement #Developer #IT #Passkey #Security #Softwareentwicklung #news
-
Triggered this nice #passkey message on a #Google account.
Looks a lot like the 7 day delay for "sensitive actions"
- https://support.google.com/accounts/answer/7162782?hl=en&co=GENIE.Platform%3DAndroid -
"Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys."
#cybersecurity #windows #google #password #passwordmanager #passkey
-
#itsec fedifriends, I'd like your opinion please: is using #Passkey a good idea, compared to strong generated passwords with #2fa ?
Providers, #bigtech in particular, seem to push hard in that direction. I wonder if it is a good idea.
In my case, I use a #passwordmanager and refuse to use biometrics.
Thanks for your #fedihelp 😁
-
A WebKit flaw causes an iCloud Private Relay IP leak during passkey authentication, exposing real user IP addresses and DNS information to servers.
-
#GWB - Google Passwortmanager: Angriff auf die Passkeys – Sicherheitsforscher erklären Pass-ta-Key-Methode - https://www.googlewatchblog.de/2026/08/google-passwortmanager-angriff-auf-die-passkeys-sicherheitsforscher-erklaeren-pass-ta-key-methode/ #passkey #Google
-
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
Comments: https://news.ycombinator.com/item?id=49176644
#HackerNews #passwordless #authentication #cybersecurity #passkey #security #risks #novel #attack #surface
-
Verizon's #passkey implementation is quite good. They're naming the Credential Manager correctly, and they're using RCS Business Messaging for proof up prior to enrollment. Well done.
-
CVE Alert: CVE-2025-71400 - better-auth - passkey - https://www.redpacketsecurity.com/cve-alert-cve-2025-71400-better-auth-passkey/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-71400 #better-auth #passkey
-
Ändert eure Passwörter nicht ständig!
-
[Перевод] Книга аутентификации
Это моя личная книга по аутентификации. Она представляет собой сборник руководств, рекомендаций и примеров по внедрению аутентификации в веб-приложениях, основанный на моем личном опыте. Книга совершенно бесплатна и не содержит рекламы. Надеюсь, она будет полезна всем, кто хочет узнать больше об аутентификации, безопасности и веб-технологиях в целом. Как следует из названия, эта книга в значительной степени посвящена системе аутентификации и авторизации для веб-приложений. Более общие вопросы безопасности см. в серии “Шпаргалки OWASP” . Если у вас возникнут какие-либо вопросы, не стесняйтесь задавать их на сервере Discord или в обсуждениях на GitHub . Разработано и поддерживается Pilcrow . Исходный код доступен на GitHub .
https://habr.com/ru/articles/1063760/
#javascript #js #go #golang #auth #authentication #authorization #passkey #basic_auth #аутентификация
-
Falha "Pass-the-Passkey" ameaça a segurança das chaves de acesso digitais. A tecnologia, prometida como substituta das vulneráveis palavras-passe, não é infalível. 🚨
-
Web.de und GMX rüsten #Passkeys nach | Security https://www.heise.de/news/Web-de-und-GMX-ruesten-Passkeys-nach-11377564.html #passkey #CyberCrime #phishing
-
Web.de and GMX add Passkeys
The United Internet subsidiaries GMX and Web.de are now introducing Passkeys. They are improving security and protection against phishing.
-
Web.de und GMX rüsten Passkeys nach
Die United-Internet-Töchter GMX und Web.de führen jetzt Passkeys ein. Sie verbessern damit die Sicherheit und den Schutz vor Phishing.
-
iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr
Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.
#IdentityManagement #IT #iXWorkshops #Passkey #ZweifaktorAuthentisierung #news
-
I am looking for a #passkey implementation on #linux which ideally integrates with [pass](https://www.passwordstore.org/) and stores its key material there.
I have found [passless](https://github.com/pando85/passless) but I have doubts if the code is trustworthy.
Does anyone have a better recommendation?