The typical webapp login process for me is anywhere from 5 to 7 steps, and I'd say I give up about 5-10% of the time after the 2nd CAPTCHA. I can't imagine this is good for anybody, and it almost surely does not reduce abuse either. Just a swirling dark pattern feeding on itself. Everyone likes to ape post-9/11 airport "security" for some reason.
#tech #dev #SecurityTheater #DarkPatterns #UI #UX #security
@abucci @hipsterelectron my new nemesis: sites that default to "use your passkey" and I'm on a fresh OS install or just never decided to make a passkey for that site.
@abucci @randomgeek @hipsterelectron The very first (and only) passkey I've experienced was "forced" on me through a dark pattern that tricked me to unintentionally click on a button. With that as my first experience, I'm forever on team No Passkey. (Also no security expert has been able to explain them in fewer than 5,000 words, which make me assume most implementations are messed up somehow.)
@troublewithwords @abucci @randomgeek @hipsterelectron if you’re interested, I’m happy to put together a shorter explanation on why they’re actually great? And also why so many sites are trying to convince users to switch.
@andrew @abucci @randomgeek @hipsterelectron No, I'm good. Seriously. No need for you to spend time on it.
@troublewithwords @andrew @abucci @randomgeek @hipsterelectron I feel ya. If someone could explain to me why they're great in _500_ words or less, I'd love that.
(I personally use passkeys, but with a Yubikey.)
@mdm @troublewithwords @andrew @abucci @randomgeek challenge-based auth theoretically doesn't (as easily) leak a persistent identity which can leaked and dumped to impersonate you and i believe it is the only standard that works with self-stewarded cryptographic authentication (yubikey) but i'm not familiar with the standard and knowing the IETF/W3C i bet it can be regulated to support a potential backdoor or especially just to serve as a surveillance technique. i'm pretty confident it's not related to TLS and separately i fully suspect TLS 1.4 to be even worse than the impressive 1.3
@mdm @troublewithwords @andrew @abucci @randomgeek yubico used to ship boxes labeled "yubico" in the mail like that doesn't compromise their customers' security. don't think they do that anymore at least i'm pretty sure mine did not do that
@abucci @randomgeek i haven't figured out any negatives to it yet and challenge-based auth seems like a good idea but i agree with this