Conversation

Oh look, another sensationalized "let's call leaving your back door open a compromise in your front door" ... "article" title (actually a paid ad, disguised as an article)

https://www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/

I say again: phrasing these as a "compromise" of passkeys when they are actually at a different step/layer only confuses people's mental models and makes them panic about the wrong thing.

It would make all the difference, and I would have zero beef, if they just phrased it as "your front door is still strong ... but you'd better check your back door and windows, too".

1
0
0

@tychotithonus I'm still reeling from that one recent article about "passkeys bad" where it highlights that uh. Resetting your password doesn't remove potentially malicious passkeys?

Which uh. Definitely an UX issue but the way it got highlit was very "passkeys bad"

In general a lot of rather funky messaging for whenever a flaw is found. Like the fact that desktop password managers had security flaws. But it's the passkeys that got highlit in that, not the fact that the rest of your password vault was just as much at risk...?

1
0
0
@saphire @tychotithonus
"a malicious application on windows can"

the system is already compromised. no auth method is safe anymore.
1
0
1
@saphire @tychotithonus
ah it's a sponsored ad by a company which i presume Fixes all of this
0
0
1