• Welcome to ASR. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Beware the scam...

Passkeys are a comfort feature that gets pushed a lot by the usual big ones.

Security behind it is good, but most people don't understand the principle completely. Passkeys move the authentification from account-base to device-base (after account auth). Control the device, have access. That's dangerous when exploits or malware are in play.

For the vendors it's a means of marketing. Once set up it has a slight lock-in effect on the customer.
 
+1 for Bitwarden. I've been using it for a few years now and the big appeal is its open source nature. Works with multiple devices and platform independent.
 
Must be an uptick in this type of scam all of a sudden like. Another (non audio) site I am on a lot just sent out virtually the same warning with a very similar story of a scammer assuming a members identity, advertising something at a too good to be true price. Making the sale, taking the money and disappearing.
 
Makes me think of the blues refrain: Nobody loves me but my mother - and she could be jivin' too.
 
@TLEDDY - it's easier to reply to your message if you add your content outside the quoted message.
And related, put a block on your phone number transfer at your mobile carrier. People have been known to hijack your phone number and then get into your account using 2FA!
People have also been known to get around the transfer block. It's been known and going on for years. Text messages are just a bad 2nd factor, so use something better, and don't trust any provider that doesn't offer something better as an option.
 
Passkeys are a comfort feature that gets pushed a lot by the usual big ones.

Security behind it is good, but most people don't understand the principle completely. Passkeys move the authentification from account-base to device-base (after account auth). Control the device, have access. That's dangerous when exploits or malware are in play.

For the vendors it's a means of marketing. Once set up it has a slight lock-in effect on the customer.
You should also need to authenticate to unlock the passkey store on the device, so controlling it isn't enough to have access. And the device can be something like a yubikey if you want to use it across multiple platforms.
 
Credential store unlocks with user auth in many cases.

Hardware factors are nice. Bitwarden supports a variety too. Can be used for passwords and passkeys.

They have next to no market share with private users though.
 
Back
Top Bottom