5 ms·
"Passwords are no longer safe, the future is passkeys. Thus you can log in with face, touch or a PIN" PIN - a personal identification number (aka a password)
by boohoo123 2y ago
"Passwords are no longer safe, the future is passkeys. Thus you can log in with face, touch or a PIN"
PIN - a personal identification number (aka a password)
This is one of those times where there is usually an ulterior motive behind this decision. Most cases in the form of power and/or control.
- acdha 2y agoIf you’re going to speculate about ulterior motives, fill in the supporting details so people can tell you’re not just promulgating conspiracy theories.
- 015a 2y agoIts a lot harder to share the passkey for e.g. your Netflix account among friends.
- acdha 2y agoSo you think that Netflix has gone to Microsoft to start a multi-year industry-wide standardization process to change how people login because that’s easier than looking at their own log files? Netflix didn’t crack down on shared passwords when they were growing rapidly but that’s not because they couldn’t.
- 015a 2y agoI don't, but yes; many seriously actually believe this is why the industry is moving to passkeys. It isn't logical, it isn't reasonable, but these are your customers.
- acdha 2y agoSo that sounds like an argument for better education, not recirculating baseless conspiracy theories.
- recursive 2y agoBaseless? Can you think of a reason why Netflix wouldn't support it for precisely this reason? Their campaign against account sharing is widely publicized. Do you think account sharing is easier or harder under passkeys? Just because it's a conspiracy theory doesn't mean it's false.
- acdha 2y agoIt’s baseless because it’s pure speculation without any evidence, or even a coherent argument for why they’d go to so much work for something they already do at much lower cost.
- recursive 2y agoI think the argument is misunderstood here. I'm not saying this is the only reason that Netflix would be in favor of passkeys, just that it's one reason, not even the main one. Here's the argument. I guess it's up to you whether you think it's coherent. 1. Netflix dislikes account sharing. They'd rather have two people pay for two subscriptions. They're a business, and are in favor of higher subscription numbers. 2. Passkeys make account sharing harder. Customer behavior modeling probably suggests that some fraction of account share-ers would create new subscriptions if they switched to passkeys. 3. Of all the reasons Netflix is in favor or against passkeys, this reason is in favor of them, via 1. and 2.
- acdha 2y agoI think the argument was a flippant response by another user riffing off of a conspiracy theorist who misunderstood how passkeys work, and while I appreciate the effort you’ve made trying to salvage it I am skeptical that Netflix would be motivated enough to be part of their hypothetical Netflix/Google/Microsoft/Apple conspiracy but not enough to even implement passkey support.
- nijave 2y agoI haven't tried--cant you share passkeys stored in your password manager?
- 015a 2y agoYes, if you're both using the same password manager. But, while you live in Silicon Valley bubbleland, most people don't. The world's most popular password manager is Excel; and sadly it does not support sharing passkeys (or, really, passkeys at all).
- acdha 2y agoBy now, wouldn’t the most popular password manager be the one builtin to Chrome, followed by Microsoft and Apple’s?
- samcat116 2y agoYou just hit the share button for the passkey in Apple/Google Passwords/your password manager
- 015a 2y agoThat only works if the share target is using the same password manager. If you asked most people "what password manager do you use" they would give you a blank stare; but sadly, the answer is rarely "I'm not using one" the answer is usually Apple or Chrome or whatever is built in and most convenient.
- vel0city 2y agoThe PIN is not a password. Two very different concepts in what they're actually used for. The password to decrypt your password database isn't your actual password to the logins contained within, its just a part of the process to get it. The PIN to unlock a passkey isn't the credential itself. Its a part of the process to be able to use the credential. Meanwhile, an account password is the credential.
- dambi0 2y agoIn some scenarios that’s really a difference without distinction though. If I have a key to my house attached to a chain so it can be used to open the door but not leave the property and then secure it in a lockbox. If someone steals the key to the lockbox they technically don’t have access to the house key but they can still rob my house
- vel0city 2y agoYour scenario makes it so the house key doesn't matter in the end though; if they're able to get to the lockbox to use the lockbox key they're already in the house and thus already able to rob it regardless of whether they got the lockbox key. In the end your door lock did nothing for you at all. I don't get how that relates to using a PIN stored in the TPM to protect your actual password, other than suggesting "well your account can be hacked without even touching your device" which I mean yeah sure. But in the end that PIN is still different from that Windows/Microsoft password. The PIN only works on that one device and gets totally invalidated after only a few failures. This is untrue of passwords which usually never get fully invalidated and are then used across multiple devices. If you manage to find out my PIN to log into device A with my Microsoft account is 1234, you don't have access to my Microsoft Account in general or on device B. If you see I log in to my device A with hunter42 (my Microsoft account password), you can now log in to my Microsoft account and every other device I'm using my Microsoft account. Is that a difference without distinction? I'd say that's quite a bit of distinction! And that's only one of the many differences!
- dambi0 2y ago
- otterley 2y agoBefore iPhones had biometric authentication, a PIN was the only means to unlock the cryptographic key that protects your data on the phone. It still is; you can bypass Face ID and Touch ID at any time by entering your PIN. So it's not like this is a new thing. It's the same concept, but applied to a PC as well.
- nijave 2y agoThe ulterior motive is compromised accounts and the support needed to deal with them is a tremendous waste of time and a liability. Switching to hardware backed authentication reduces risk and support. Face/touch/PIN are an additional layer to protect against hardware theft.