home.social

#passkey — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passkey, aggregated by home.social.

fetched live
  1. Wie dumm ist eigentlich die #Passkey Lösung der #Telekom ?
    Es ist nicht ordentlich #FIDO2 sondern muss auf #Google #Apple oder #Windowshello erfolgen. Mit einem #Yubikey #Token2 oder so funktioniert es nicht. Auch lässt sich nur eine (in Zahlen: 1!) APP oder Gerät für #2FA wie ein #Autenticator hinterlegen...
    Und die #MagentaAI kann einem das nicht beantworten. Nach längerer Konversation bietet sie an mit dem Hinweis "Service Team" an den Support durchzustellen.
    Das klappt natürlich auch nicht. Macht man das, fragt die #AI worum es geht. Ob Internet oder Mobilfunk...

    Das ist ein Konzern, zu dem #TSystems gehört? Geil!

  2. «Insgesamt sei es „etwas besorgniserregend“, dass Menschen vermehrt Passkeys nutzen, ohne deren Funktionsweise zu verstehen.»
    - Verständlich. Hatte vor Kurzem einer Kollegin geholfen wegen einem Zugang. Hatte gesehen, dass sie diesen mit dem Passkey geschützt hat und war mega beeindruckt. Hatte ihr das auch gesagt und sie so: «Was ist ein Passkey???»

    Studie zum Umgang mit #Passkeys: Nutzer wissen zu wenig Bescheid | Security heise.de/news/Studie-zum-Umgan #Passkey

  3. Studie zum Umgang mit Passkeys: Teilweise gefährlicher als Passwörter

    Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. Beim Umgang damit gibt es aber teils erhebliche Probleme, hat ein US-Forschungsteam ermittelt.

    heise.de/news/Studie-zum-Umgan

    #Internet #IT #Security #Passkey #Wissenschaft #news

  4. Nochmals viele Neuerungen und zahlreiche Breaking Changes in .NET 11.0 Preview 7

    Die siebte Preview bringt abermals eine Spracherweiterung für C#, verbesserte Komprimierungs-APIs und neue Features für Blazor.

    heise.de/news/Nochmals-viele-N

    #NET #ASPNET #C #IT #Microsoft #Passkey #news

  5. “Malware installed on a device running #macOS, #iOS, and #Android, for instance, has no ability to defeat this isolation unless the OS itself is compromised […]. The lone exception is #Windows. […] Windows apps generally run with all the privileges of the user, [and] it doesn’t prevent unsandboxed apps such as #malware from accessing the data of a sandboxed app.”

    #passkey #passtakey

    arstechnica.com/security/2026/

  6. Triggered this nice #passkey message on a #Google account.

    Looks a lot like the 7 day delay for "sensitive actions"
    - support.google.com/accounts/an

  7. "Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager's synced passkeys to take over accounts, bypass user verification, and extract passkey private keys."

    bleepingcomputer.com/news/secu

    #cybersecurity #windows #google #password #passwordmanager #passkey

  8. #itsec fedifriends, I'd like your opinion please: is using #Passkey a good idea, compared to strong generated passwords with #2fa ?

    Providers, #bigtech in particular, seem to push hard in that direction. I wonder if it is a good idea.

    In my case, I use a #passwordmanager and refuse to use biometrics.

    Thanks for your #fedihelp 😁

  9. My 3A Mini "broke", the string connection was just torn off, now it is a big hassle to remove the key from USB ports..*sigh*. I guess if I buy another it will be a Nitrokey 3C (No NFC). Are there any other better solutions already? (please no if possible)

  10. Verizon's #passkey implementation is quite good. They're naming the Credential Manager correctly, and they're using RCS Business Messaging for proof up prior to enrollment. Well done.

  11. [Перевод] Книга аутентификации

    Это моя личная книга по аутентификации. Она представляет собой сборник руководств, рекомендаций и примеров по внедрению аутентификации в веб-приложениях, основанный на моем личном опыте. Книга совершенно бесплатна и не содержит рекламы. Надеюсь, она будет полезна всем, кто хочет узнать больше об аутентификации, безопасности и веб-технологиях в целом. Как следует из названия, эта книга в значительной степени посвящена системе аутентификации и авторизации для веб-приложений. Более общие вопросы безопасности см. в серии “Шпаргалки OWASP” . Если у вас возникнут какие-либо вопросы, не стесняйтесь задавать их на сервере Discord или в обсуждениях на GitHub . Разработано и поддерживается Pilcrow . Исходный код доступен на GitHub .

    habr.com/ru/articles/1063760/

    #javascript #js #go #golang #auth #authentication #authorization #passkey #basic_auth #аутентификация

  12. Falha "Pass-the-Passkey" ameaça a segurança das chaves de acesso digitais. A tecnologia, prometida como substituta das vulneráveis palavras-passe, não é infalível. 🚨

    🔗 tugatech.com.pt/t88123-falha-p

    #falha #pass #passkey 

  13. I am looking for a implementation on which ideally integrates with [pass](passwordstore.org/) and stores its key material there.

    I have found [passless](github.com/pando85/passless) but I have doubts if the code is trustworthy.

    Does anyone have a better recommendation?