Re: OT: Passkey usage
Tim via users <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.general |
|---|---|
| Organization | Me, organised? Are you kidding?! |
| Message-ID | <[email protected]> |
On Fri, 2026-08-14 at 11:29 +0100, Patrick O'Callaghan wrote: > It's better than a password because (in theory) it never leaves the > device, and hence is not vulnerable to an eavesdropper. Think of it as > one half of an asymmetric key pair. As long as the system isn't weak against replay of a certificate (something listens to yours, copies it, then sends the same thing to a bad system to impersonate you). It shouldn't be possible, there's supposed to be cross-checking, and maths that do something unique each time you use your credentials, but some badly designed systems have failed that way. Of course passwords are *more* vulnerable to that. But people put a bit too much faith in passkeys as being immune to the problem. There is one thing that passwords are supposedly better at, in the sense that *if* your system will not let you store your password you have to type it in each time to use it. With certificates, they're installed and ready to be used. -- uname -rsvp Linux 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64 (yes, this is the output from uname for this PC when I posted) Boilerplate: All unexpected mail to my mailbox is automatically deleted. I will only get to see the messages that are posted to the mailing list. -- _______________________________________________ users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new