Hacker News new | ask | show | jobs
by throwawayqqq11 921 days ago
Your government id card is not widely adopted as method of authentification, i guess. This is where this new pass key approach comes in. My concern is, that this new method might completely replace old fashioned passwords. And once every one is used to have a hardware token, the next step of only accepting or selling government approved devices is a small one. This could could ultimately make anonymity impossible. Because you dont control the hardware or the spec.

Imagine being required to have and use your govID for simply everything, because there is no alternative.

This is not a risk of secure authentification, which passwords can also provide.

$Corps loved to harvest phone numbers as a second factor despite a second fall back email address would be at least as secure as SS7 communication. But phone numbers are tied more strongly to your identity so more valuable for the data brokers.

This is the same thing actually. Tieing identity to something you have and not something you alone know. Something external.

Having a single external dependency for all your identities sounds like a good idea to you? For facists and data brokers it certainly does.

To me, this is an attack on anonymity and i know that i sound paranoid. Lets wait for the enshitening.

1 comments

You DON’T have to trust any company or government for passwordless authentication. Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one).

At this point, you’re just making shit up about something you don’t understand.

> Don’t want to use your phone? Use a hardware key instead. Don’t want to use a hardware key? Use an open source solution like Bitwarden (and it’s not the only one).

You're ignoring the fact that WebAuthn can require attestation, which will remove device choice from the equation.

You havent understood my point.

> Nothing compares to the secrecy of password.

Because they are soley internal to you.

Yes, you can generate passkeys at will ... and then you give them away to a usb dongle or HSM, from which some day you might not be able to export them, because vendors love their locked in customers.

I am talking about control and yes, my concerns are speculation but reasonable to me, when you look at pretty much all the recent development. From not-WEI over DRM, to right to repair and on and on.