this post was submitted on 08 Mar 2025
747 points (100.0% liked)

Technology

69702 readers
3030 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 20 points 1 month ago (12 children)

What would you propose replace passwords to not be susceptible to those things?

I personally like how secure and non intrusive passwords are, especially when using a self hosted password manager synced with git.

[–] [email protected] 9 points 1 month ago (6 children)

It is hard to do well which is why I worry. Google probably has the best overall account security, you could fo worse than modeling after them.

The short answer to your question is Passkeys. But you need a whole system of account recovery around them.

[–] [email protected] 1 points 1 month ago (5 children)

Oh, you can easily bypass passkeys with automation. Don't even need an image recognition model, just a QR-code scanner like zbarimg.

But i never tried googles passkey feature since it never seemed as secure as a 48 char computer generated password. So I'm not sure exactly how it works.

[–] [email protected] 12 points 1 month ago* (last edited 1 month ago)

Go read the FIDO threat model if you want to understand how it protects against specific attacks. It is pretty secure.

https://fidoalliance.org/specs/fido-v2.0-id-20180227/fido-security-ref-v2.0-id-20180227.html

load more comments (4 replies)
load more comments (4 replies)
load more comments (9 replies)