this post was submitted on 05 Aug 2025
37 points (91.1% liked)

Hacker News

2242 readers
437 users here now

Posts from the RSS Feed of HackerNews.

The feed sometimes contains ads and posts that have been removed by the mod team at HN.

founded 10 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] jbk@discuss.tchncs.de 11 points 1 day ago (6 children)

You can't phish users with passkeys.

[–] hansolo@lemmy.today 1 points 1 day ago* (last edited 1 day ago) (5 children)

While true, session hijacking is the already prolific vulnerability left wide open that passkeys actually make harder to deal with. (Edit: as in mitigate the attack once is happened)

Instead of a scammer getting grandma to read her SMS TOTP on the phone (easier than Sim swapping, but only barely), she gets a call to go to a URL and enter her passkey manager PIN to OK sessions across everything she has passkeys for. Most already open in 800 open browser tabs.

And when her passkey is compromised, how quickly will Google customer service act to get her a new one? A few days? Longer?

What problem is actually solved here? Passkeys are about saving money for the companies on password reset server time.

[–] WhatAmLemmy@lemmy.world 4 points 1 day ago (3 children)

Passkeys are about saving money for the companies on password reset server time.

Lol, no. They don't care about the extra 0.001% expense. Passkeys are mainly to protect the average user from their own stupidity. Grandma is far more likely to use the same shit password across many sites. Most average users are.

[–] killwill@feddit.nl 1 points 1 day ago (1 children)

Yeah this guy is grossly overestimating the intelligence of businesses when it comes to software. I've seen a major company spending 20000+ a month on aws for servers they never used. And that was just for a single site, I can only imagine what's going on in other branches of the company.

[–] hansolo@lemmy.today 1 points 1 day ago

Not at all, Google, Meta, and MS spend a lot of resources resetting passwords across literally tens of millions of accounts. It ads up at scale, and it's not even insignificant at the enterprise level.

https://www.bleepingcomputer.com/news/security/the-true-and-surprising-cost-of-forgotten-passwords/

load more comments (1 replies)
load more comments (2 replies)
load more comments (2 replies)