this post was submitted on 28 Feb 2025
535 points (93.4% liked)

memes

12174 readers
2277 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to !politicalmemes@lemmy.world

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/AdsNo advertisements or spam. This is an instance rule and the only way to live.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[โ€“] yesman@lemmy.world 5 points 2 days ago* (last edited 2 days ago) (1 children)

I didn't consider the friction of integrating it into your existing process because I use a manual password manager. But who is saying you should replace a password manager with passkeys? It was always meant to be a parallel system.

Edit: I just wanted to add that people like you and I who have "solved" our credentials problems are a tiny minority. Passwords are shit. Just because we've grown accustomed to them doesn't change that.

[โ€“] WhatAmLemmy@lemmy.world 5 points 2 days ago

You'll find that nobody has a problem with passkeys specifically. They have a problem with the implementation, and companies forcing passkeys onto users who don't want or need them.

I don't need passkeys because I use a password manager. My threat model requires that I can restore my password manager, all 2FA, and regain full access to all my accounts from anywhere in the world, even if a natural disaster occurs and all my devices are destroyed.

Passkeys and SMS 2FA are a direct threat to my threat model, and I can't help but feel they're designed to further entrench surveillance capitalism, and the invasion of privacy as a prerequisite for security.