Hacker News with Generative AI: Passwords

Magic Links Have Rough Edges, but Passkeys Can Smooth Them Over (rmondello.com)
Independent media venture 404 Media recently published a post titled, “We Don’t Want Your Password”. The piece is a cogent explanation of the problems with password-based accounts online followed by a defense of the website’s login strategy, magic links, in the face of feedback about them being inconvenient and difficult to use.
Microsoft won't let customers opt out of passkey push (theregister.com)
Microsoft last week lauded the success of its efforts to convince customers to use passkeys instead of passwords, without actually quantifying that success.
LastPass hacked, users see millions of dollars of funds stolen (techradar.com)
Apple Releases iCloud Passwords Add-On for Firefox (macrumors.com)
Apple now has a dedicated iCloud Passwords add-on designed for the Firefox browser, which means Firefox users can access passwords and logins stored in the Passwords app or iCloud Keychain when using Firefox on a PC or Mac.
Will passkeys ever replace passwords? Can they? Here's why they should (theregister.com)
Will passkeys ever replace passwords? Can they?
Becoming physically immune to brute-force attacks (2021) (seirdy.one)
This question might not be especially practical, but it’s fun to analyze and offers interesting perspective regarding sane upper-limits on password strength.
Apple Passwords’ generated strong password format (rmondello.com)
This post briefly summarizes part of a talk I gave in 2018. All information in this post has been accessible on YouTube since then. There is no new information or news in this post.
The War on Passwords Is One Step Closer to Being Over (wired.com)
“Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced on Monday.
New passkey specifications will let users import and export them (9to5mac.com)
Passkeys were introduced two years ago, and they replace traditional passwords with more secure authentication using a security key or biometrics. To make the technology even better, the FIDO Alliance published on Monday new specifications for passkeys, which ensure a way to let users import and export them.
Coming soon: Securely import and export passkeys (1password.com)
Passkeys are superior to passwords in almost every way. They’re simpler to use because there’s nothing to memorize, type out, or paste in. They’re also always strong and come with multi-factor authentication built right in. In short, passkeys are awesome.
Always have a comma in your password, if part of a leak it will break the CSV (toot.cafe)
NIST's New Password Guidelines Will Eliminate Periodic Changes and Special (socket.dev)
NIST (National Institute of Standards and Technology) is set to update its recommendations for authentication and authenticator management as part of a revision to its Digital Identity Guidelines.
NIST to forbid requirement of specific passwords character composition (mastodon.social)
Passwords have problems, but passkeys have more (world.hey.com)
We had originally planned to go all-in on passkeys for ONCE/Campfire, and we built the early authentication system entirely around that. It was not a simple setup!
What Is a Password Hash? (tuta.com)
Why most password requirements are silly. Also, here's our flavor (medium.com)
Chrome will now prompt some users to send passwords for suspicious files (arstechnica.com)
About Passkey – the password-free tech Apple is betting on (fastcompany.com)
Apple unveils 'Passwords' manager app at WWDC 2024 (zdnet.com)
Ask HN: 1 passkey per device, or store it in password manager? (ycombinator.com)
Debian Sid No-Feature KeePassXC Package (github.com/keepassxreboot)
Passkey Implementation: Misconceptions, pitfalls and unknown unknowns (corbado.com)
No more 12345: devices with weak passwords to be banned in UK (theguardian.com)