• rumba@lemmy.zip
    link
    fedilink
    English
    arrow-up
    28
    ·
    2 days ago

    Half a cryptographic key that you can’t easily give to someone over the phone by accident.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        9 hours ago

        I’ve been using certificate based auth on https for ages on my ops stuff. Most devices support just slapping an SSL/TLS key into their os, but not everything.

        But when I wanted to use it for Jellyfin, I found TVs and sticks aren’t all straightforward.

        In your link, they closed that ticket as not planned because they intend to implement FIDO’s secure exchange protocols. https://github.com/keepassxreboot/keepassxc/issues/11363

        It should (hopefully) be secure when they get done.

        • enumerator4829@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          I mean, the passkey is still in there. It’s protected by convention. It’s a bearer token wrapped in a password manager, presented as a revolution.

          We have the technology, can we please pour the same amount of resources into what we’ve already had for decades? Passkeys solve the UX issue for ”normal people”, that’s the selling point.