Well that’s OK; we recently discovered that things like passkeys usually aren’t using the TPM anymore anyway. Most stuff stored in there can be routed around via tokens stored on main storage.
I’m honestly amazed by this. Passkeys were the touted solution to all our human password problems. How is it that something so critical went unnoticed until recently?
You’d think this would be something that gets caught before release. What went wrong?
IIRC, the Passkey spec did not specify the use of specialized hardware for key storage. So if this a case where people chose convenience over security without realizing they were making the tradeoff?
That would still be phenomenal. Who leads these sort of things and why is such a blatant issue unnoticed until most of us are affected?
It doesn’t matter how good a plan is if we can’t follow it. So what stops this issue from continuing to plague the next “great” solution to password management?
Well that’s OK; we recently discovered that things like passkeys usually aren’t using the TPM anymore anyway. Most stuff stored in there can be routed around via tokens stored on main storage.
I’m honestly amazed by this. Passkeys were the touted solution to all our human password problems. How is it that something so critical went unnoticed until recently?
You’d think this would be something that gets caught before release. What went wrong?
IIRC, the Passkey spec did not specify the use of specialized hardware for key storage. So if this a case where people chose convenience over security without realizing they were making the tradeoff?
That would still be phenomenal. Who leads these sort of things and why is such a blatant issue unnoticed until most of us are affected?
It doesn’t matter how good a plan is if we can’t follow it. So what stops this issue from continuing to plague the next “great” solution to password management?
deleted by creator