home.social

#passkeys — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #passkeys, aggregated by home.social.

fetched live
  1. #Passkeys gelten als der große Fortschritt in der Kontosicherheit und werden von Unternehmen wie Google, Apple und Microsoft aber auch von Behörden wie dem #BSI aktiv beworben - aber wie gut sind sie in der Praxis wirklich?

    Das hat nun eine #Laborstudie u.a. der Cornell University untersucht und gelangt im Ergebnis zu einer strukturellen Lücke zwischen dem Sicherheitsversprechen von Passkeys und ihrer tatsächlichen Handhabbarkeit für die User im Störfall:

    news.cornell.edu/stories/2026/ #cybersecurity

  2. Token is a mostly misunderstood term in IT technology:

    Some think to know how expensive their AI use is, others expect to receive profits via cryptocurrencies, but we all use it to enter the password / passkeys for authentication after every click on the web.

    It’s all true, but one thing isn’t marketing propaganda.

    #token #ai #cryptogrpahy #myopinion #cryptocurrency #itsecurity #web #opinion #internet #authenticate #password #passkeys #marketing #propaganda

  3. WebAuthn L3, the technical specification and API that powers #passkeys, is now a #W3C Recommendation!

    blog.timcappalli.me/p/webauthn

  4. I am amused, how many initiatives must I launch, really solid business-forward ideas, load them into a standard torpedo shell and fire them into the fogbank of the C-Suite? I’ve got the #AI one languishing, might as well also do this #passkeys foolishness too. It'll likely be around $30k a year for this company I work for. I wonder how many of these torpedoes I can launch and watch as they plop into the fogbank of management? Ah well, it'll come and then the suffering… oh well, Uwu. #work

  5. So it appears that #Microsoft is sunsetting their voice and sms gateways that run through their wretched #2FA boondoggle, the security colander of #MFA. They’re going to switch to #Passkeys and while I'm still very salty about the entire category of passkeys, how I suggested it years ago and it was all a big joke cause I was a ninny, and here we are, the ninny was right! Anyhow, so now that we've got a timer from #Microsoft, I've renewed my interest in #1Password.

  6. «Insgesamt sei es „etwas besorgniserregend“, dass Menschen vermehrt Passkeys nutzen, ohne deren Funktionsweise zu verstehen.»
    - Verständlich. Hatte vor Kurzem einer Kollegin geholfen wegen einem Zugang. Hatte gesehen, dass sie diesen mit dem Passkey geschützt hat und war mega beeindruckt. Hatte ihr das auch gesagt und sie so: «Was ist ein Passkey???»

    Studie zum Umgang mit #Passkeys: Nutzer wissen zu wenig Bescheid | Security heise.de/news/Studie-zum-Umgan #Passkey

  7. This #Yubico #YubiKey Standard from approximately 2012 was on my personal key ring ever since on a daily basis. It has been my first FIDO2 token.

    It now ceased to work after approx. 14 years as it's no longer recognized by a computer when plugged in.

    Fortunately, it's been mostly replaced by a newer key months ago. So no data loss. Furthermore, I always had a second token that was registered with the same services anyway.

    That's my personal data point for durability of #FIDO2 #security hardware tokens. Not bad, I'd say. 👍️

    I still prefer FIDO2 HW tokens over #passkeys because HW tokens are not prone to #phishing: karl-voit.at/FIDO2-vs-Passkeys/ (German)

    #2FA #MFA #securitytokens #publicvoit #20241005_FIDO2VsPasskeys

  8. I've really loved #authentik but over time, it growed beyond the needs of someone running just some services in his #homelab. Then I stumbled upon #PocketID and discovered that - ditching passwords and only focusing on #passkeys - this one matched my needs in terms of speed, standards and flexibility even more.

    Check it out at https://pocket-id.org - it's easy to deploy and even more easier to deal with. Great, modern application supporting #OpenID Connect and #OAuth 2.0!

    Solutions like authentik or Keycloak are still great but - at least in my case -rather taking a sledgehammer to crack a nut but hey - home is no Enterprise!

    @homelab @homelab_de

  9. #posteo kann jetzt auch #passkeys. Dies ist sicher ein Schritt in die richtige Richtung.

    Allerdings klappt die Registrierung noch nicht mit #Firefox, weder mit #yubikey noch #keepassxc. Das ist frustrierend, aber wer mit dieser Technologie hantiert, ist Frust wohl gewohnt. Kinderschuhe überall...

    Was aber klappt, ist die Registrierung von yubikey unter #Chromium. Wenn man das gemacht hat, klappt auch der Login unter Firefox.

    Die Begründung erscheint mir noch nicht so 100% motiviert:

    > Wir bieten Passkeys als Passwort-Alternative an, weil sie ein neuer Anmelde-Standard sind und manche Kundinnen und Kunden sie nutzen möchten.

    #security

  10. Pass-ta-key attacks show why Windows passkeys live in the cloud, not the TPM

    If this matters to you, share it.

    1ban.news/pass-ta-key-windows-

    #1ban #pass #key #windows #passkeys #tech

  11. #Passkeys werden Anfang 2027 die Standard-Anmeldemethode im Microsoft-365-Ökosystem 😎 Wenn ihr euch bisher noch gar nicht damit beschäftigt habt, ist jetzt ein guter Zeitpunkt. Ich habe die meisten Passkeys in #Bitwarden (Software), einige wichtige auf dem #Yubikey (Hardware).

  12. 9to5 Google: Google Password Manager passkeys could be at risk with new ‘Pass-ta-key’ attack. “Passkeys are becoming more popular as a safer alternative to traditional passwords, but some cracks are starting to show after one group successfully bypassed Google’s Chrome-based passkeys using what they call the “Pass-ta-key” attack method.”

    https://rbfirehose.com/2026/08/05/9to5-google-google-password-manager-passkeys-could-be-at-risk-with-new-pass-ta-key-attack/
  13. The Best Password Managers for Secure Passwords and Passkeys

    📰 Original title: 8 Best Password Managers (2026), Tested and Reviewed

    🤖 IA: It's not clickbait ✅
    👥 Users: It's not clickbait ✅

    View full AI summary en.killbait.com/the-best-passw

    #technology #passwordmanagers #passkeys

  14. Just posted the slides and audio recording from my session with @iamkale from Identiverse 2026 which talked through some of the biggest misconceptions about #passkeys throughout 2025.

    blog.timcappalli.me/p/preso-id