#publicvoit

3 posts · Last used Aug 22

Mit #PassTaKey wurden 3 schwere Sicherheitslücken in Verbindung mit #Google #Chrome und #Passkeys veröffentlicht, die unter #Windows eine komplette Übernahme aller Passkeys ermöglichen. Inwiefern sich das Risiko einer fehlerhaften Softwareimplementierung kompensieren lässt, habe ich auf meinem Blog beschrieben: Authentifizierung mit FIDO2 und Passkeys https://karl-voit.at/FIDO2-vs-Passkeys/ Kurz: nach wie vor ist das non-plus-ultra ein bis zwei #FIDO2 Hardware-Tokens: Ziemlich sicherer Schutz gegen #Phishing, wohingegen Passkeys leider nicht immer helfen, obwohl es fälschlicherweise oft anders behauptet wird. #20241005_FIDO2VsPasskeys #publicvoit #Authentifizierung #TOTP #GoogleAuthenticator #MicrosoftAuthenticator #Sicherheit
1
0
1
0
Replying to
@mkristensson@thepit.social True. However, some megacorps are extending passkeys to allow for sharing and moving keys. Unfortunately, you lose the phishing protection with that as well. So yes, some passkeys setups aren't protection against phishing any more. 😞 Therefore, I use user/password + #FIDO2 hardware token when it *really* needs to be secure and #TOTP for the rest. Even with passkeys, FIDO2 hardware tokens don't support those convenience features where #passkeys lose #phishing protection. More on https://karl-voit.at/FIDO2-vs-Passkeys/ (German) #security #publicvoit
0
0
0
0
Replying to
@richard@hemmer.land I would love to read about this! #Mastodon blog article comments ftw! Background: similar idea of mine on https://karl-voit.at/2026/02/18/Vorschlag-minkorrekt-Fediverse-statt-Forum/ and implemented it on https://karl-voit.at/2026/04/19/lazyblorg-recent-features/ #lazyblorg #publicvoit
1
3
0
0
You've seen all posts