Comment on Google will now make passkeys the default for personal accounts

<- View Parent
MeanEYE@lemmy.world ⁨1⁩ ⁨year⁩ ago

But that’s the whole thing we are trying to solve here. We are trying to eliminate human factor and by extension bad habits people have when it comes to security. So expecting people to use good passwords and pins for keys will be the same as expecting people to have good passwords for accounts. Perhaps even worse because of claims it’s better security so people might even relax more.

Also timeouts with pins and passwords mean very little once someone has your device. This is why I don’t consider it good two-factor. PIN might be in your head, but nothing is preventing someone brute forcing it. Once you image the device you can do whatever you want. With credit cards, you’d need ATM to keep doing it and lockout is a serious problem there.

It’s a step in right direction for sure, but I’d prefer if keys didn’t depend on PIN or password.

source
Sort:hotnewtop