6 ms·
In the tech world, security is mostly just a theater , it is used to push though unwanted and unpopular things, like access control, privacy invasion, etc... A
by tacker2000 5mo ago
In the tech world, security is mostly just a theater , it is used to push though unwanted and unpopular things, like access control, privacy invasion, etc...
All this signing business, leads to one party having the final say, and guess what, they are going to abuse that power...
- balamatom 5mo agoSacrifice principles for pragmatism and you lose both.
- palata 5mo agoI think it's just like in software in general: most software is bad, but it doesn't mean that all software is bad and unnecessary. Most security is done badly, but it doesn't mean that security is unnecessary. But I agree: TooBigTech has TooMuchPower.
- coldpie 5mo ago> But I agree: TooBigTech has TooMuchPower. Passkeys are here to improve your login security! All you have to do is give complete control over your ability to log in to a service to one of three American big tech companies. Yay!
- palata 5mo agoOr you spend 5 minutes reading about them and use a passkey you actually own? Many times, people choose TooBigTech. People are generally waaaay too lazy to even consider spending some brain cycles on that.
- coldpie 5mo agoUnless the service you are trying to log in to requires you to only use an approved authenticator, as is explicitly supported by the spec[1]. [1] "To be very honest here, you risk having KeePassXC blocked by relying parties." https://github.com/keepassxreboot/keepassxc/issues/10407#issuecomment-1994182200 https://github.com/keepassxreboot/keepassxc/issues/10407#iss... More examples here https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-still-have-problems/#:~:text=It%27s%20Still%20Vendor%20Lockin https://fy.blackhats.net.au/blog/2025-12-17-yep-passkeys-sti...
- palata 5mo agoRight, that sucks. But the service could also only allow you to use the Google SSO, it's not really a problem coming from the passkeys...
- ratmeadow 5mo agoBecause some people realised that insurance is the ultimate form of security? Why prevent failure when the consequences of failure can simply be offloaded to others?