Ancestors

Written by zaknenou@lemmy.dbzer0.com on 2024-08-24 at 18:39

Is it really that easy to hack someone's Discord? Is it the same with: Telegram, Twitter, facebook ...ect ? and does this work if I'm accessing Discord through Firefox ?

https://lemmy.dbzer0.com/post/26547520

=> More informations about this toot | More toots from zaknenou@lemmy.dbzer0.com

Written by xylogx@lemmy.world on 2024-08-25 at 13:56

Passkey is resistant to these attacks, but user adoption is not widespread enough for Discord to be able to mandate it.

=> More informations about this toot | More toots from xylogx@lemmy.world

Written by toastal@lemmy.ml on 2024-08-26 at 11:35

What is wrong with good ol’ TOTP & FIDO2?

=> More informations about this toot | More toots from toastal@lemmy.ml

Written by xylogx@lemmy.world on 2024-08-26 at 13:09

Passkey is FIDO2.

=> More informations about this toot | More toots from xylogx@lemmy.world

Toot

Written by toastal@lemmy.ml on 2024-08-26 at 14:43

Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs. These key pairs profoundly improve security.

– developer.apple.com/passkeys/

Based on FIDO2/WebAuthn but unlike them, passkeys are those things Apple & Google have been pushing that live on their servers + one specific device in its secure enclave you as as a user aren’t allowed to look into. FIDO2 is usually tied to some USB security token.

=> More informations about this toot | More toots from toastal@lemmy.ml

Descendants

Written by gibson@sopuli.xyz on 2024-08-27 at 02:41

you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave.

=> More informations about this toot | More toots from gibson@sopuli.xyz

Written by toastal@lemmy.ml on 2024-08-27 at 04:48

These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them.

=> More informations about this toot | More toots from toastal@lemmy.ml

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113028852651202220
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
281.847464 milliseconds
Gemini-to-HTML Time
1.486548 milliseconds

This content has been proxied by September (3851b).