11 ms·
And yet that's not enough, even when someone very definitely knows better: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/ https
by ipsi 1y ago
And yet that's not enough, even when someone very definitely knows better: https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/ https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mail...
Turns out that under certain conditions, such as severe exhaustion, that "sus filter" just... doesn't turn on quickly enough. The aim of passkeys is to ensure that it _cannot_ happen, no matter how exhausted/stressed/etc someone is. I'm not familiar enough with passkeys to pass judgement on them, but I do think there's a real problem they're trying to solve.
- diggan 1y agoIf you're saying something is less secure because the users might suffer from "severe exhaustion", then I know that there aren't any proper arguments for migrating to it. Thanks for confirming I can continue using OTP without feeling like I might be missing something :)
- skydhash 1y ago> If you're saying something is less secure because the users might suffer from "severe exhaustion" Something "$5 wrench" https://xkcd.com/538/ https://xkcd.com/538/
- simonw 1y agoPasskeys genuinely do protect against severe exhaustion attacks.
- diggan 1y agoYeah, but they genuinely also prevent you from moving away from companies in the process of enshittification, since the whole export/import thing seemingly hasn't been figured out or even less been deployed yet. Besides, if you ignore security alarm-bells going off when exhausted, I'm not sure what solution can 100% protect you.