• CubitOom@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    12
    ·
    2 days ago

    Oh, you can easily bypass passkeys with automation. Don’t even need an image recognition model, just a QR-code scanner like zbarimg.

    But i never tried googles passkey feature since it never seemed as secure as a 48 char computer generated password. So I’m not sure exactly how it works.

    • 4am@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      That’s a pretty wild claim. It almost sounds like you don’t know what a passkey is. Explain.

      • CubitOom@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        6
        ·
        edit-2
        2 days ago

        Oh I don’t know what it is, sorry I thought I made that clear. But a quick search on the internet said it was basically 2fa with a qr code and since the issue was how it would protect Lemmy from bots I just thought it wouldn’t be hard for a bot to read a qr code.

        • Feathercrown@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          1 day ago

          Bruh that’s gotta be one of the worst trains of thought I’ve seen recently ngl. I don’t even know how passkeys work and I know that. Based on your understanding, you could log into someone’s account just by reading a QR code. Which of these is more likely:

          • The entire cybersecurity community mysteriously and completely forgot that machines can read QR codes (which is, by the way, literally the entire purpose of a QR code)

          • You don’t understand how passkeys work

          How arrogant do you have to be?