• Evotech@lemmy.world
    link
    fedilink
    arrow-up
    2
    ·
    5 months ago

    It’s not about encryption/security it’s about creating something that can’t be phished.

    We know that 2fa is secure. But if an attacker can trick you into giving them the code, or typing it in a fake box. Then they own you.

    Passkeys are made so that there’s nothing to give, nothing to type. You must control the device.

        • ramjambamalam@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 months ago

          I’d love to see the state of online banking if everyone were to manage their own ssh keys

          Most people couldn’t figure out how to download a binary release from a GitHub repo, much less clone it, regardless of HTTP or SSH.