this post was submitted on 26 Sep 2026
390 points (94.9% liked)

Technology

88272 readers
3099 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
(page 4) 5 comments
sorted by: hot top controversial new old
[–] GreenShimada@lemmy.world -2 points 1 day ago (7 children)

Passkeys are worthless trash, invented explicitly to save Microsoft and Google money on password reset server time.

They do not solve session hijacking. Any attacker that has your granny on the phone to read them her password can also tell granny to go to a link and give them her session cookies.

[–] Technus@lemmy.zip -4 points 1 day ago

That's what CSRF mitigations are for.

Do you actually understand how any of the modern web works or does your knowledge stop at W3Schools tutorials from the mid-2000s?

load more comments (6 replies)
[–] Technus@lemmy.zip -2 points 1 day ago (11 children)

I feel like there's some potential in password-derived passkeys, which would get around the storage and hardware lock-in issues. It'd essentially be a master password like for BitWarden, but instead of needing an app to store a bunch of generated passwords, the master password could be all you need to authenticate.

Most of the sources of compromise for regular users would be eliminated because the password never leaves the client.

load more comments (11 replies)
load more comments
view more: ‹ prev next ›