These are public posts tagged with #passkey. You can interact with them if you have an account anywhere in the fediverse.
iX-Workshop: Passwortlose Authentifizierung mit Passkeys, FIDO, SSO und mehr
Wie man FIDO2 und SSO in Webdienste integriert: Konzepte, Protokolle und Best Practices für eine sichere Authentifizierung mit und ohne Passwort.
#IdentityManagement #IT #iXWorkshops #Passkey #Verschlüsselung #news
Wie man FIDO2 und SSO in Webdienste integriert: Konzepte,…
heise onlineOccasionally Google prompts me to create a passkey immediately after I signed in with one. I cancel and move on. No big deal, but it seems quite obtuse. They know I have multiple registered and that I just used one of them. #Fido2 #Passkey #Passkey #Google #GoogleWorkspace
FÜr alle, die es noch nicht wissen, aber interessiert:
#ct3003 veröffentlicht die neuen Videos jetzt auch auf #peertube
#makertube #ct #ITmagazin #IT
Themen bisher: #KI #PassKey #UnplugTrump
Schaut doch mal rein, damit sie auch weiter im Fediverse veröffentlichen.
https://makertube.net/c/ct_3003_und_heise/videos
A home for makers, musicians, artists and DIY folks
MakerTube#Microsoft is killing off passwords completely, in favour of passkeys. I think this will alienate a lot of people... thoughts? https://mindsconnected.tech/index.php?showtopic=1079&view=getnewpost #password #security #cybersecurity #windows #windows10 #windows11 #passkey #tech
The next-generation tech forum, from Windows to Linux,…
mindsconnected.techA passkey is a secure, easy-to-use replacement for passwords. It uses your device's built-in security (Face ID, fingerprint, PIN, etc.) to log you into a website or service, without requiring you to remember or type anything.
#passkey #password #security
https://www.techspot.com/article/2971-passkeys-explainer/
Google-Passkey einrichten – so geht's | heise online
https://www.heise.de/tipps-tricks/Google-Passkey-einrichten-so-geht-s-10326284.html #Google #Passkey
c't 3003: Das Problem mit Passkeys
Passkeys sind sicherer als Passwörter, aber Apple, Google & Co. schränken die Nutzung ein. c't 3003 zeigt, wie man sie plattformübergreifend einsetzen kann.
#ct #Entertainment #IT #Mobiles #Passkey #Passwörter #Security #Wissen #news
Passkeys sind sicherer als Passwörter, aber Apple,…
heise online@yacc143 FYI: #Passkeys and #FIDO2 (= "device-bound #passkey" which can be divided into "platform-" and "roaming-authenticators") are identical except the #cloud-sync mechanism (as of my current understanding).
So unfortunately, they get mixed up or are considered as totally different things. Both is wrong.
In reality, they are very similar except that FIDO2 hardware tokens ("device-bound passkeys" only in their "roaming-authenticator" variant) are designed that way, that Passkeys are not being able to extracted from the device (at least for the moment).
Therefore, users of HW tokens can't be tricked into transferring their passkey to a rogue third party, which is possible with all other Passkey variants. Therefore: passkeys are NOT #phishing-resistant in the general case.
#TroyHunt fell for a #phishing attack on his mailinglist members: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/
Some of the ingredients: #Outlook and its habit of hiding important information from the user and missing #2FA which is phishing-resistant.
Use #FIDO2 with hardware tokens if possible (#Passkeys without FIDO2 HW tokens are NOT phishing-resistant due to the possibility of being able to trick users with credential transfers: https://arxiv.org/abs/2501.07380) and avoid Outlook (or #Microsoft) whenever possible.
Further learning: it could happen to the best of us! Don't be ashamed, try to minimize risks and be open about your mistakes.
Note: any 2FA is better than no 2FA at all.
#email #malware #security #OTP #TOTP #Passkey #haveibeenpwned #Ihavebeenpwned
You know when you're really jet lagged and really tired…
Troy Hunt@techlore proton pass is good in that your data on proton pass is fully #encrypted. So if you use a hardware based #passkey such as a #yubikey to secure the main account, and have all your other accounts within use software based passkeys and 2FA, wouldn't be as much of a risk even if Proton Pass got breached as a service.
@technotenshi #Passkeys are not prone to #phishing according to my understanding of:
https://arxiv.org/abs/2501.07380
The paper describes that it's possible to fool Passkey owners to transfer their #Passkey to attackers: "Another concern could be social engineering, where a user is tricked into sharing a passkey with an account controlled by an attacker."
However, the authors disagree with my interpretation.
The only really secure method is hardware #FIDO2 tokens where the secrets can't leave the device.
With passkeys, the FIDO Alliance introduces the ability…
arXiv.org«PassKey Account Takeover in All Mobile Browsers: Phishing PassKeys credentials using browser intents»
I hope this is not confirmed and if so knows @passkeysdev or someone of you?
https://mastersplinter.work/research/passkey/
#passkey #phishing #itsec #browser #passkeys #account #dev #webdev #takeover #askfedi #CVE_2024_9956 #CVE20249956 #pleaseboost #plsboost
Phishing PassKeys credentials using browser intents
Tobia RighiLa gente de Zen Browser anuncia el soporte de Passkey para la próxima actualización
#ZenBrowser #passkey #firefox
Some say passkeys are clunky — this startup wants to change that
https://techcrunch.com/2025/03/11/some-say-passkeys-are-clunky-this-startup-wants-to-change-that/
#news #tech #technology #security #privacy #passkey #internet
#Passkey: Hat jemand Lust, im Juli beim WebMontag etwas über Passkeys zu erzählen?
@itsfoss Good so far.
On a side note it should have added passkey support at level,shouldn't it?
#ubuntu #opensource #foss #passkey
Certains services en ligne passent maintenant par une #passkey pour s'authentifier. (typiquement les GoogleBidules, mais pas que et ce n'est que le début askyp')
Mon gestionnaire de mots de passe (bitwarden) ne peut enregistrer qu'une clé par couple identifiant - mot de passe sur un service.
Mais on dirait ?? les passkey sont liées aux appareils, et donc mon accès à Bidules OK sur 1 seul PC,
sur mon autre ordi ça marche pas, et je vois pas comment faire... ?