▲ 54 ▼ [Youtube video]: Is it really that easy to hack someone's Discord? Is it the same with: Telegram, Twitter, facebook ...ect ? and does this work if I'm accessing Discord through Firefox ? (www.youtube.com) submitted 2 years ago* by zaknenou@lemmy.dbzer0.com to c/privacy@lemmy.ml 34 comments fedilink hide all child comments
[–] xylogx@lemmy.world 7 points 2 years ago (2 children) Passkey is resistant to these attacks, but user adoption is not widespread enough for Discord to be able to mandate it. permalink fedilink source hideshow 4 child comments replies: [–] _Atlas_@lemmy.world 3 points 2 years ago (1 child) Wtf, if it's such a huge security bonus, why wait for user adoption, especially if token stealing is an issue? permalink fedilink source parent hideshow 2 child comments replies: [–] xylogx@lemmy.world 2 points 2 years ago Change is hard. It has been a long road to get where we are today: major OS and Browser vendor support. Users now need to change their behavior. permalink fedilink source parent [–] toastal@lemmy.ml 2 points 2 years ago (1 child) What is wrong with good ol’ TOTP & FIDO2? permalink fedilink source parent hideshow 2 child comments replies: [–] xylogx@lemmy.world 2 points 2 years ago (1 child) Passkey is FIDO2. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 4 points 2 years ago (1 child) Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs. These key pairs profoundly improve security. -- https://developer.apple.com/passkeys/ Based on FIDO2/WebAuthn but unlike them, passkeys are those things Apple & Google have been pushing that live on their servers + one specific device in its secure enclave you as as a user aren’t allowed to look into. FIDO2 is usually tied to some USB security token. permalink fedilink source parent hideshow 2 child comments replies: [–] gibson@sopuli.xyz 1 point 2 years ago (1 child) you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent
[–] _Atlas_@lemmy.world 3 points 2 years ago (1 child) Wtf, if it's such a huge security bonus, why wait for user adoption, especially if token stealing is an issue? permalink fedilink source parent hideshow 2 child comments replies: [–] xylogx@lemmy.world 2 points 2 years ago Change is hard. It has been a long road to get where we are today: major OS and Browser vendor support. Users now need to change their behavior. permalink fedilink source parent
[–] xylogx@lemmy.world 2 points 2 years ago Change is hard. It has been a long road to get where we are today: major OS and Browser vendor support. Users now need to change their behavior. permalink fedilink source parent
[–] toastal@lemmy.ml 2 points 2 years ago (1 child) What is wrong with good ol’ TOTP & FIDO2? permalink fedilink source parent hideshow 2 child comments replies: [–] xylogx@lemmy.world 2 points 2 years ago (1 child) Passkey is FIDO2. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 4 points 2 years ago (1 child) Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs. These key pairs profoundly improve security. -- https://developer.apple.com/passkeys/ Based on FIDO2/WebAuthn but unlike them, passkeys are those things Apple & Google have been pushing that live on their servers + one specific device in its secure enclave you as as a user aren’t allowed to look into. FIDO2 is usually tied to some USB security token. permalink fedilink source parent hideshow 2 child comments replies: [–] gibson@sopuli.xyz 1 point 2 years ago (1 child) you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent
[–] xylogx@lemmy.world 2 points 2 years ago (1 child) Passkey is FIDO2. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 4 points 2 years ago (1 child) Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs. These key pairs profoundly improve security. -- https://developer.apple.com/passkeys/ Based on FIDO2/WebAuthn but unlike them, passkeys are those things Apple & Google have been pushing that live on their servers + one specific device in its secure enclave you as as a user aren’t allowed to look into. FIDO2 is usually tied to some USB security token. permalink fedilink source parent hideshow 2 child comments replies: [–] gibson@sopuli.xyz 1 point 2 years ago (1 child) you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent
[–] toastal@lemmy.ml 4 points 2 years ago (1 child) Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs. These key pairs profoundly improve security. -- https://developer.apple.com/passkeys/ Based on FIDO2/WebAuthn but unlike them, passkeys are those things Apple & Google have been pushing that live on their servers + one specific device in its secure enclave you as as a user aren’t allowed to look into. FIDO2 is usually tied to some USB security token. permalink fedilink source parent hideshow 2 child comments replies: [–] gibson@sopuli.xyz 1 point 2 years ago (1 child) you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent
[–] gibson@sopuli.xyz 1 point 2 years ago (1 child) you can still use a yubikey or even a password manager like keepassxc with passkeys, no need for any google/apple or even secure enclave. permalink fedilink source parent hideshow 2 child comments replies: [–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent
[–] toastal@lemmy.ml 1 point 2 years ago These passkeys want to be unique per site/services & many hardware tokens only have a handful of slots for storage which means such dedicated don’t really work & storing them on say your laptop with your other passwords probably isn’t ideal with Keypass. Many security experts don’t see the advantage over a good hardware token + unique password. Like Big Tech trying to reinvent XMPP with RCS, I feel they are trying to do the same with passkeys so they benefit them. permalink fedilink source parent