Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Well, the assumption is that ownership of the device and ability to unlock it (face | fingerprint | passcode) present 2 factors for authentication of the FIDO local keychain.

Passwords are time-tested and failed approach. They rely on user using different passwords for each system. Most people suck at passwords. Just look at your parents (or youngsters - your grandparents) - they probably suck. We probably would at their age also, except we use tooling like password managers that are still frustratingly difficult for non-techies.



can we stop with this ageism? There is plenty of teenagers or people in their 20s or 30s with ludicrous passwords. Unless you are a techie, passwords are chores and nobody wants to do complex chores.


Agreed, let me restate - most non-techies really suck at passwords. The rest of us are probably overconfident in our own op-sec.

Regardless I stand firm that passwords are a poor authentication standard, and the time is nigh for us to move on.


Passwords have their problems but this will not make things more simple so I really doubt it will be more secure in the end. If it's adopted it will just change attack methods.

On my side, I do not trust any company mentioned in the article and do not use any of their product. If i'm required to have anything to do with them, I'll just be locked out (and I don't think I'll be the only one)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: