- cross-posted to:
- [email protected]
- cross-posted to:
- [email protected]
- Big Tech has implemented passkeys in a way that locks users into their platforms rather than providing universal security
- Passkeys were developed to replace passwords for better account security, but their rollout by Apple and Google has limited their potential
- Proton Pass offers passkeys that are universal, easy to use, and available to everyone for improved online security and privacy.
That is not the takeaway here.
The takeaway is Passkeys are great technology but as implemented by Google, Microsoft, and Apple fall short of what they could be.
This isn’t some “owned by the billionaire class”. It’s an open standard that’s why Bitwarden and Proton both have implementations. Big tech of course provided implementations that are not as portable as possible, that’s all that’s going on here.
There’s really not some big conspiracy to kill kittens or whatever. Passkeys are far more secure (and for most people far more usable) than passwords.
then get them implemented by someone else useably. that open authentication login garbage they pushed years ago was also supposed to be an open standard, but you can only use it if you lock yourself in to facebook/google to this day. i still have to use a different password for each damn website still.
id like to see its opennes at work in the real world, in practice, first.
Proton, Bitwarden, 1Password, Yubico (via the Yubikey), and others (including big tech) already have their own independent implementations(?)
Even Keypass has at least a partial implementation https://github.com/keepassxreboot/keepassxc/pull/8825
i’m sure they do, but can i login to most websites using them?
99/100 i get the option to use facebook, google or just bite the bullet and make an account. i’m talking about this by the way:
Yes. Any website that has implemented passkey authentication can be logged into by any Passkey provider. There are no websites that “Only accept Apple passkeys”
I think you better understood their question; thanks for jumping in.
It will get there… https://passkeys.directory/ https://passkeys.2fa.directory/us/
It’s still relatively new technology.