Re: OT: Passkey usage

Tim via users <[email protected]>
Newsgroups gmane.linux.redhat.fedora.general
Organization Me, organised? Are you kidding?!
Message-ID <[email protected]>
On Fri, 2026-08-14 at 11:29 +0100, Patrick O'Callaghan wrote:
> It's better than a password because (in theory) it never leaves the
> device, and hence is not vulnerable to an eavesdropper. Think of it as
> one half of an asymmetric key pair.

As long as the system isn't weak against replay of a certificate
(something listens to yours, copies it, then sends the same thing to a
bad system to impersonate you).  It shouldn't be possible, there's
supposed to be cross-checking, and maths that do something unique each
time you use your credentials, but some badly designed systems have
failed that way.

Of course passwords are *more* vulnerable to that.  But people put a
bit too much faith in passkeys as being immune to the problem.

There is one thing that passwords are supposedly better at, in the
sense that *if* your system will not let you store your password you
have to type it in each time to use it.  With certificates, they're
installed and ready to be used.

-- 
 
uname -rsvp
Linux 3.10.0-1160.119.1.el7.x86_64 #1 SMP Tue Jun 4 14:43:51 UTC 2024 x86_64
(yes, this is the output from uname for this PC when I posted)
 
Boilerplate:  All unexpected mail to my mailbox is automatically deleted.
I will only get to see the messages that are posted to the mailing list.
 

-- 
_______________________________________________
users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.