A separate question regarding logging in with biometrics. WTF is this sign in with your PIN, face, or fingerprint option that eBay wants me to choose? Is this separate from a passkey? I can't find any documentation on this.

Ah, OK. This is just another term for passkey (in this case one that's resident on my Windows laptop).

So even when I already have a passkey synced through 1Password, eBay is going to suggest I create a separate passkey that's native to the OS I happen to be using at the moment. This is only going to confuse people and discourage the adoption of passkeys.

I love the technology behind passkeys, but they're not (yet) anywhere close to qualifying as usable security.

@dangoodin All of that is WebAuthN basically (also called more or less correctly FIDO2). Wikipedia article on it is not bad: en.wikipedia.org/wiki/WebAuthn

Follow

@pmevzek @dangoodin Except with very specific differences/additions that really mess up some use cases.

fy.blackhats.net.au/blog/2024-

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.