this post was submitted on 03 May 2025
16 points (90.0% liked)

Technology

2569 readers
375 users here now

Which posts fit here?

Anything that is at least tangentially connected to the technology, social media platforms, informational technologies and tech policy.


Rules

1. English onlyTitle and associated content has to be in English.
2. Use original linkPost URL should be the original link to the article (even if paywalled) and archived copies left in the body. It allows avoiding duplicate posts when cross-posting.
3. Respectful communicationAll communication has to be respectful of differing opinions, viewpoints, and experiences.
4. InclusivityEveryone is welcome here regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, education, socio-economic status, nationality, personal appearance, race, caste, color, religion, or sexual identity and orientation.
5. Ad hominem attacksAny kind of personal attacks are expressly forbidden. If you can't argue your position without attacking a person's character, you already lost the argument.
6. Off-topic tangentsStay on topic. Keep it relevant.
7. Instance rules may applyIf something is not covered by community rules, but are against lemmy.zip instance rules, they will be enforced.


Companion communities

!globalnews@lemmy.zip
!interestingshare@lemmy.zip


Icon attribution | Banner attribution


If someone is interested in moderating this community, message @brikox@lemmy.zip.

founded 1 year ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] BombOmOm@lemmy.world 17 points 1 day ago (2 children)

The gold standard is providing something you know (a password) alongside something you have (an OTP or fingerprint). This is two-factor auth in a nutshell.

using your face, fingerprint, or PIN

You leave fingerprints and images of your face everywhere you go; and in the case of someone spoofing those, there is zero way to change either. Such public information is not the foundations of a secure system.

And a PIN is just a shorter, shittier password. Why the hell would we replace a normal password with the least secure, most shitty version of a password?

[–] jacksilver@lemmy.world 5 points 1 day ago

The whole idea is about moving to passkeys, which are like super passwords unique to a device. The face/finger/pin is the second Auth to use the passkey.

Not saying this is good or bad, but msoft does have an faq about passkeys

The major thing I still don't understand is, without a password, how do you authenticate people who lost access to their device/passkey.

[–] theneverfox@pawb.social 2 points 1 day ago

Easier passwords are often better, since people are less likely to try to get around them

Pins are basically simple passwords that fingerprint your device to decide when it needs another auth method

It's not a bad idea, in theory at least