The typical webapp login process for me is anywhere from 5 to 7 steps, and I'd say I give up about 5-10% of the time after the 2nd CAPTCHA. I can't imagine this is good for anybody, and it almost surely does not reduce abuse either. Just a swirling dark pattern feeding on itself. Everyone likes to ape post-9/11 airport "security" for some reason.
#tech #dev #SecurityTheater #DarkPatterns #UI #UX #security
@abucci @hipsterelectron my new nemesis: sites that default to "use your passkey" and I'm on a fresh OS install or just never decided to make a passkey for that site.
@abucci @randomgeek @hipsterelectron The very first (and only) passkey I've experienced was "forced" on me through a dark pattern that tricked me to unintentionally click on a button. With that as my first experience, I'm forever on team No Passkey. (Also no security expert has been able to explain them in fewer than 5,000 words, which make me assume most implementations are messed up somehow.)
@troublewithwords @abucci @randomgeek @hipsterelectron if you’re interested, I’m happy to put together a shorter explanation on why they’re actually great? And also why so many sites are trying to convince users to switch.
@andrew @abucci @randomgeek @hipsterelectron No, I'm good. Seriously. No need for you to spend time on it.
@troublewithwords @andrew @abucci @randomgeek @hipsterelectron I feel ya. If someone could explain to me why they're great in _500_ words or less, I'd love that.
(I personally use passkeys, but with a Yubikey.)
@abucci @randomgeek i haven't figured out any negatives to it yet and challenge-based auth seems like a good idea but i agree with this