In Australia it's pretty great: my driver's license can be provided by an app on my phone and legally must be accepted if it is. So between that and NFC payment support, a phone is the only thing I need to remember to operate outside the house.
It's pretty great as long as it doesn't evolve into them no longer printing the cards and requiring use of their app, consequently on one of their approved OSes.
I mean yes but that is a case of the slippery slope fallacy: the existence of a future possible decision does not affect whether a current decision is a good one.
If they try to move in that direction, we can protest it then. Denying ourselves a useful capability now doesn't stop it from happening anyway, nor make it more likely.
I personally live in a country with a large religious population that rejects the smartphone, so thankfully I personally have not encountered a situation where needing a smartphone is vital. However we've seen many people right here on HN mention how some specific vital service - often government or banking - does require a smartphone.
In my HN Threads feed, the very next item is another HN user mentioning how they have difficulty paying for parking spaces without a smart phone, from this very page. Search "and sadly accept the cost of our principles" on this page to find it.
But I have no interest in winning internet arguments. You win, the cookie isn't worth it to me.
Keepass2Android without network permissions saving the file to a folder monitored by Syncthing is pretty good though - it keeps responsibilities nicely separated.
If passkeys were meant to be user friendly then there'd be a secure optical transfer mode to QR code them from device to device with the screen and camera.
Easy to implement (receiver flashes a public key, sender encrypts to that key and flashes the QR code back).
That it doesn't exist for a protocol meant to work with phones tells you exactly where the thinking was headed.
That they have purposely put effort into preventing you from doing that shows you everything you should need to know.
The entire point of passkeys is yanking the control over authentication out of the hands of people. These companies don't want you to be able to let someone else log in as you.
That's the entire point.
The problem they are solving has absolutely nothing to do with security.
FIDO authenticator attestation is dead for consumer-facing RPs. Apple made the right call and simply refuses to support it outside of MDM environments.
The entire value proposition, and the reason big sites are pushing them, is they take the user out of the loop of authentication. You are no longer authenticating the user, you're authenticating the users device.
For websites you don't have to worry about cookie theft and dealing with the support load of users needing their accounts reset or dealing with fraud. You can also do some level of attestation to hardware which makes automated account creation more difficult.
For the user it offers no additional benefits. You still have something secret that gets presented to a website to login. Password managers solved this problem. But now for some reason you can't log in when you buy a new laptop.
Why should I recognize that as valid interest, when it's straight out hostile to me? I know why they are doing that. It doesn't oblige me to accommodate their selfish interests.
It is playing nice to criticize things. It's not just "different priorities", passkeys have intentional trade offs which cause them to be "more secure" but in ways that users do not want because it negatively affects them. The intentional trade off made in the name of "more security" makes them wildly inconvenient and risks causing massive lockout. Like removing all the staircases from people's homes and replacing them with climbing walls all in the name of "security". You can't just diffuse that by say "well we want banks to be more secure, we have different priorities."
I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys. If they don't have their phone, or it's dead, or it breaks, or is stolen, they just can't access their account anymore. They have no idea how they work or what they're trading off, nor do they understand that they should have prepared for this scenario ahead of time somehow. Upon telling them "yeah you have to use your phone now that you have a passkey" they all universally say "wtf, that's stupid, I never want to have that happen again, I will never use a passkey again."
Passkeys should never have been built for general audiences, they are a huge mistake, I hope they cease to be relevant and die due to everyday folks realizing they're inconvenient and the "more secure" gains ain't worth it for the usability nightmares.
"I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys."
In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys.
As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor.
So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully.
Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys.
Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things.
There's a brief period when you join any company where you really want to improve things, and then about a year in the system has asserted towards the mean.
Nothing to do with schooling, every thing to do with business structures.
Also how many predictions did they make? Everyone always goes looking the economist who predicted the last recession, it's just so weird how it's usually a different person each time!
I spend a lot of time on the Internet and other then sounding vaguely familiar I have no idea who Yudkowsky is and have never read any of their output.
The assumption "spent a lot of time on the Internet" is still through a framing you're assuming is more general even then.
HackerNews straight up has sub demographics who likely barely interact based on article interests.
I kinda overdid it with a tape library (40 tapes capacity, LTO-9), but I'm using it for my company's AI model backups. _That_ setup was about $12k.
I had a smaller setup before, with a simple external LTO-5 drive. Used drives are now are about $300, and you can probably find them cheaper. And LTO-5 is the minimum realistic version, it's the first one that supports LTFS and it has reasonable tape capacity.
The Trump admin will be 2 years out of office by the time the Virginia deliveries are slated to start.
If America goes fully fascist by then, then the wisdom of that contract will be the least of our problems (or to put it another way: what's the alternative? Because if you're serious about the threat it's "crash course nuclear weapons and a delivery vehicle" if you want to guarantee our sovereignty).
The problem with deciding you're so powerful you can force everyone to follow you is you actually have to force everyone to follow you and it turns out that's super expensive and costs you a lot of power in terms of committed assets to do it.
reply