• Em Adespoton@lemmy.ca
    link
    fedilink
    English
    arrow-up
    12
    ·
    il y a 2 jours

    Well that’s OK; we recently discovered that things like passkeys usually aren’t using the TPM anymore anyway. Most stuff stored in there can be routed around via tokens stored on main storage.

    • partofthevoice@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      il y a 21 heures

      I’m honestly amazed by this. Passkeys were the touted solution to all our human password problems. How is it that something so critical went unnoticed until recently?

      You’d think this would be something that gets caught before release. What went wrong?

      IIRC, the Passkey spec did not specify the use of specialized hardware for key storage. So if this a case where people chose convenience over security without realizing they were making the tradeoff?

      That would still be phenomenal. Who leads these sort of things and why is such a blatant issue unnoticed until most of us are affected?

      It doesn’t matter how good a plan is if we can’t follow it. So what stops this issue from continuing to plague the next “great” solution to password management?