EPISODE · Apr 12, 2025 · 46 MIN
0: Passkeys
from Runtime Arguments · host Jim McQuillan & Wolf
There are many scams, some to get your password(s), some just for money. Join us as Wolf tells everything he knows and together we discuss a new way to protect your online accounts.Show notes:Lists of login methods:https://testdriven.io/blog/web-authentication-methods/ https://www.logintc.com/types-of-authentication/Who implements Passkeys?https://www.passkeys.com/websites-with-passkey-support-sites-directoryhttps://fidoalliance.org/passkeys-directory/https://www.keepersecurity.com/passkeys-directory/The three things that come together to make passkeys:Using key pairs, like SSH: https://www.ssh.com/academy/ssh/public-key-authenticationBiometric authentication, you're already used to it from your phoneNew User Interface "ceremonies"Which password managers support passkeys?1Password (our personal favorite)BitwardenDashlaneGoogle Password ManagerKeeperNordPassRoboFormA little about password managers:Almost any password manager is better than no password manager at all so do your research. Find the best one for you. Make sure it answers these questions:Does it run on all the platforms you care about?Does it have a pricing model you like?Does it use a cloud service, or not, or of your choice, in a way that you like?Does the password service itself have access to your keys?What kind of secrets can it keep?Passkey descriptions and implementation documentsThe FIDO alliance: https://fidoalliance.org/passkeys/Google (for developers): https://developers.google.com/identity/passkeys/developer-guidesApple (for developers): https://developer.apple.com/passkeys/Wolf's top three personal digital security recommendationsUse a password manager (it should support passkeys). See above.Once you create a passkey for a specific service; change your previous password. The new one should be generated by your password manager and you should never use it unless you absolutely must.Make sure your device is secureUse biometric authenticationHave a strong password. Your password manager can generate one made from words. Easy to remember; hard to guess.Make sure you know how to force your device to require a password. You can be tricked or forced to authenticate biometrically. Law enforcement can't force you to reveal a password; and if you're careful, you can't be tricked out of it.Be aware of your surroundings. Bad actors can "shoulder surf" and get your password, or cameras. It's just like the old days at the ATM. You don't want a person right behind you to see your PIN.Hosts:Jim McQuillan can be reached at [email protected] can be reached at [email protected] us on Mastodon: @[email protected] music:Dawn by nuer self, from the album Digital Sky
Embed this episode
What this episode covers
There are many scams, some to get your password(s), some just for money. Join us as Wolf tells everything he knows and together we discuss a new way to protect your online accounts. Show notes: Lists of login methods: https://testdriven.io/blog/web-authentication-methods/ https://www.logintc.com/types-of-authentication/Who implements Passkeys? https://www.passkeys.com/websites-with-passkey-support-sites-directoryhttps://fidoalliance.org/passkeys-directory/https://www.keepersecurity...
NOW PLAYING
0: Passkeys
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.