Yeah you get it. I just have a bone to pick with colleagues that embrace anti-user methods needlessly. Convenience = security is a “slow = fast” type of spiel.
Comment on Passkeys Explained: The End of Passwords
artyom@piefed.social 2 months agoconvenience is security (change-my-mind lol)
Not at all. Typically they’re opposites. But I understand what you’re trying to say. More convenience leads to better security.
Septimaeus@infosec.pub 2 months ago
sem@lemmy.blahaj.zone 2 months ago
Don’t forget the intermediary
Slow is smooth, and smooth is fast.
Septimaeus@infosec.pub 2 months ago
Slow is smooth, and smooth is fast.
Haha that’s the one ;)
Passerby6497@lemmy.world 2 months ago
If it’s more convenient to be insecure than secure, users will pick insecure every time. There’s a reason there are so many bad password in the top passwords in breach dumps.
I have to tell myself every time I go through some of my login flows that inconvenience to me means more so to an attacker, but most people don’t have an adversarial mindset and just want it to work.
artyom@piefed.social 2 months ago
User inconvenience is not at all the same thing as security.
Passerby6497@lemmy.world 2 months ago
No, but the two tens to be correlated.
Example, MFA authentication is a security feature, but inconvenient as shit with low or no lifetime. Same complaints about short lived sessions on app sites. Especially when every login requires MFA…
artyom@piefed.social 2 months ago
MFA can be a variety of different things. In the case of passkeys, a prompt comes up on the screen, you click it, and that’s it. It’s both secure and convenient. That’s why it’s great.