• Evotech@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    3 days ago

    You know what u don’t like. Fucking xøcode sent to my email or a «magic link».

    Srsly fuck off. Let me type my password

  • ouch@lemmy.world
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    3
    ·
    4 days ago

    Good article.

    Currently passkeys are too much of a vendor lock-in to big tech.

    Bitwarden support alone does not change that.

    • Clusterfck@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      22
      arrow-down
      1
      ·
      4 days ago

      Microsoft 365 implementation of passkeys is sacrilegious somehow.

      It requires only the Authenticator app from Microsoft and can use nothing else to create the passkey. The way this is implemented on iOS means that Authenticator comes up as an autofill option BUT IT ONLY SUPPORTS M365 and is useless for anything else. Leave it to Microsoft to take an open standard and bastardize it to the point of it being MORE CONVENIENT to just type a damn password.

      • tehBishop@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 days ago

        The authenticator requirement was for regular MFA, with passkey you can use others like yubikey. BUT your admin can lock it to certain vendors so they could have selected Microsoft only.

        • Clusterfck@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          3 days ago

          I’m the admin. Every time I try to open it up, I only get guides for doing it on a regular, personal MS account.

    • turmacar@lemmy.world
      link
      fedilink
      English
      arrow-up
      22
      ·
      4 days ago

      I agree the passkey user experience needs work, but man do I enjoy it over the haphazard ‘passwordless’ website login that just sends you an email.

      I get it, they’re just skipping an attack vector and basically relying only on ‘2FA’. But now I have to go to a different app/tab, copy a code, and return to the site instead of letting the password manager fill stuff in for me. Some, like kickstarter, let you still have a 2FA code enabled so you have to grab your code from whichever authenticator and go to your email. Really nice login experience out of nowhere one day. \s

      • Joelk111@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        4 days ago

        The best implementation of this I’ve seen has to be Ghost, an open source self-hostable newsletter/patreon thing. They detect what email provider you have and when you enter your email, will display a link to open your inbox. It’s super neat, and I haven’t seen it anywhere else, and I’m also not sure how they do it. For something self-hostable, I’ll definitely take one less attack vector.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 days ago

          A DNS lookup on a domain says who runs the email server for email users on that domain (that’s how email senders figures out how to send you messages), and if that host is a known one then you can just pull the link to show. If you’re self hosting email then a few solutions can be recognized and login shown by guessing that the email software’s default URL pattern is used.

    • mysticalone@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      4 days ago

      bitwarden went from working great to buggy on browsers. sometimes the browser passes the request to the extension but most times goes to the os

  • kestrel7_7@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    3 days ago

    I appreciate this article. Passkeys kinda came out of nowhere to me and I haven’t liked them since day one. So it’s nice to have my gut feeling vindicated with some actual info.

  • dropdrip@lemmy.ml
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    9
    ·
    edit-2
    4 days ago

    This isn’t a good article @ouch. It’s dull, meandering and conflates issues.

    Both Apple and Google want your identity anchored to their operating systems.

    That’s true regardless of passkeys and why is Microsoft excluded here?

    Logging into accounts on devices you own is the ideal scenario for passkeys. When you have to handle a colleague’s computer, it gets much more inconvenient. You could plug in a hardware key, but you don’t always have access to the ports.

    What sort of drivel is this? Is anyone reading the article? I doubt it. Sorry, I’m not logging into important accounts on a colleague’s computer, regardless of being unable to squat and plug in a usb-dongle. The last statement even concedes that passkeys are an improvement for 99% of the user-population. It’s an improvement for 100% of the user-population. Like usual this is just drivel generated from friction around ‘newness’. It’s different–which automatically becomes scary for some users. The writing is just not coherent and there’s zero critique on passkey’s design and technicalities, of which there are things to criticize.

    Get a physical passkey and if you have more than 100 accounts you have a problem. Buy two and use one as a backup in case you lose your first. Keep it in a safe and if you forget your safe’s combination… well, I guess we should abolish safes too: terrible account recovery support there. Yikes!

    Passkey’s themselves can be protected with a PIN–the software I’ve used does not limit it to numbers. It can be your ‘master password’ if you want. This is a technical complaint of mine as all software I’ve used reference it as a PIN (personal identification number), which means numbers only. Except other characters are allowed. I’m not sure what the official spec. states.

  • hummingbird@lemmy.world
    link
    fedilink
    English
    arrow-up
    82
    ·
    5 days ago

    Sadly did not dig into the whole “the other side decides which device you are allowed to use” topic, a feature inherently build into passkeys.

    • Schal330@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      ·
      5 days ago

      I think that is only an issue based on what Passkey attestation is configured by the relying party? From what I have read a lot of public facing companies implementing it will have passkey attestation statements configured as None, which typically means there isn’t an authenticator certificate verification.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        7
        ·
        4 days ago

        Only companies issuing their own passkeys on company hardware has a reason to enable attestation (forcing use of company approved devices throughout). Any public facing service has no reason to use attestation.

  • warm@kbin.earth
    link
    fedilink
    arrow-up
    62
    arrow-down
    1
    ·
    5 days ago

    I think their biggest weakness is the vendor lock in. Using a 3rd party password manager is the best solution for most people, so they arent locked to their phone. But they are right in saying none of it is quite ready.

    I think the article is forgetting, they are password replacements, not account recovery replacements. Realistically, people are just as likely to forget a password, and account recovery proceedures still have to be in place. I dont see the issue there.

    Passkeys are good they are just being pushed before properly fully developed, but we are slowly getting there.

    • Kangae_Hishiryo@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      6
      ·
      4 days ago

      The main problem is if that you lose the device that’s physically attached to the passkey… You’ll lose your account.

      I’d just prefer a biometrics-first approach.

      Unless hackers started cutting people’s fingers, which is something just too risky for a rational hacker to do so it’s more than improbable, biometrics are way more secure, consistent, battle-tested and most important, more convenient and, by design, unforgettable.

      • warm@kbin.earth
        link
        fedilink
        arrow-up
        11
        arrow-down
        1
        ·
        4 days ago

        That’s why you shouldn’t use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.

        Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.

        • Kangae_Hishiryo@scribe.disroot.org
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          8
          ·
          4 days ago

          Biometrics are NOT shit.

          And the recovery process is useless if you don’g have acess to your recovery method. Passkeys create the Ouroboros kind of situation.

          • warm@kbin.earth
            link
            fedilink
            arrow-up
            4
            ·
            4 days ago

            Passkeys are just more convenient replacements to passwords, ideally suited for a password manager flow.

            For most people, this works really well and is a lot better than remembering loads of passwords. It’s easier to get people to remember a single stronger password and use passkeys to login to services.

            The whole lose access thing isnt as big of a deal breaker as you make it sound (It literally works the same as it does now with passwords). Considering the large amount of people that forget their passwords and constantly reset them, passkeys can help. There’s a reason popular sites just ask you for a code from an email now instead of even prompting for your password.

            You want to use biometrics to individually login to services, great. But what about those of us who don’t want to rely on biometrics? That’s where passkeys do both jobs.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        edit-2
        4 days ago

        Biometrics is inherently not securable and the only viable method of using it ever is locally only to unlock a different secret, which actually can be secure.

        Most biometrics is trivial to duplicate, fingerprints can replicated from photographs.

        Biometrics are battle tested and got annihilated in every conflict. It’s a total loser.

  • muzzle@lemmy.zip
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    3
    ·
    4 days ago

    For users who previously reused passwords across all their sites, passkeys are a huge step-up.

    That is exactly why passkeys are a good thing. Basically everyone reused passwords everywhere.

        • redjard@reddthat.com
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          2
          ·
          4 days ago

          android doesn’t allow 3rd party apps to use passkeys nor autofill 2fa consistently. For passkeys, you are forced to use google services for it, or loose access, making it pointless. TOTP codes meanwhile can at least be copied and pasted manually from a password manager.

            • redjard@reddthat.com
              link
              fedilink
              English
              arrow-up
              2
              ·
              3 days ago

              It’s android version dependent. Only 14 and up support 3rd party providers.

              Passkeys are supported on devices that run Android 9 (API level 28) or higher.

              On many devices, Credential Manager stores passkeys to Google Password Manager by default. Users can choose other password managers as its passkey providers in the System Settings on Android 14 or higher.

              Given the slowness of android version rollouts, this will be an issue for a long time.

              I also think supporting older androids is pushing apps to do it the “wrong” way and making it google specific.

              • Zak@lemmy.world
                link
                fedilink
                English
                arrow-up
                4
                ·
                3 days ago

                14 and up seems to be about 80% of users, and I suspect there’s a correlation between people who want to use passkeys with a third party password manager and being within two major versions of current.

      • Glitchvid@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        Really depends on what you mean by passkey, since it’s actually a fairly vague term for a bundle of technologies.

        I don’t really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.

        But I’m a big fan of hardware 2fa using non-resident keys (“passkey” lite); I’ll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 days ago

          Even pw synced passkeys at least have the benefits of both being phishing resisting + replay protected, as well as being able to use the TPM chip for extra local protection.

          Hardware keys are logically simpler though

      • arrowMace@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        4 days ago

        It’s a false dichotomy to have one or the other. I use passkeys as a quicker and more convenient way to log in to some sites, but I still have passwords in my password manager as a fallback.

        • Scrollone@feddit.it
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 days ago

          Some websites prevent you from using a password if you set up a passkey.

          Pass keys are horrible.

          • Flagstaff@programming.dev
            link
            fedilink
            English
            arrow-up
            4
            ·
            3 days ago

            It seems like what’s actually horrible would be those websites’ implementation. But yeah, I’m definitely sticking with a manager.

    • Cort@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      2
      ·
      4 days ago

      Maybe 5 or 10 years ago, but who doesn’t use a password manager these days? They generate random passwords and remember them for you

      • muzzle@lemmy.zip
        link
        fedilink
        English
        arrow-up
        29
        ·
        4 days ago

        Do you know any non tech people, especially over 40? Literally none of them uses a password manager.

        • Cort@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          4 days ago

          Most of the non-techy people I know use the password manager built into their Web browser at the very least.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            4
            ·
            4 days ago

            “use” I bet it just saves everything automatically, and they don’t even know their passwords are there. just “oh look, my password has appeared, lets click it!”

          • nullroot@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            4 days ago

            In my experience you’re more likely to find a sticky note on the desk with passwords than someone using a password manager, 2fa, or an ounce of ‘common’ sense.

      • laranis@lemmy.zip
        link
        fedilink
        English
        arrow-up
        5
        ·
        4 days ago

        So we should be using passkeys to access our password managers that generate random passwords and remember them for us! Ultimate protection.

      • GreyEyedGhost@piefed.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        My current employer will not authorize the use of a password manager. I have a key fob for my Microsoft account, and another account does phone verification. I use one password. If they don’t want to put the effort in for account security then neither do I. I use a password manager for nearly all my other accounts.

      • Bluescluestoothpaste@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 days ago

        I just remember my passwords idk lol. I never understood the logic of a password manager, someone hacks your manager they have everything in your life? Rather just run the risk of getting hacked one account at a time rather than they all get hacked at once when they get my password manager.

        • Flagstaff@programming.dev
          link
          fedilink
          English
          arrow-up
          3
          ·
          edit-2
          3 days ago

          So make the manager’s password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It’s just too much brainpower to remember individual websites’ passwords. All important ones have 2FA anyway.

          Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.

  • Passerby6497@lemmy.world
    link
    fedilink
    English
    arrow-up
    29
    arrow-down
    1
    ·
    4 days ago

    I really wish that SQRL had taken off, as it solved most of the problems noted. It was effectively passkeys that you generated on the fly based on your private key (which you can back up and restore to other platforms if necessary) and the website domain by scanning a QR code (or clicking rh QR code if your on the same device) and sends the signed challenge to the website to auth you.

    No need to login to your manager on random systems, no issues with platform lock-in, no worries about dedicated hardware, no worry about losing your access if your device dies (assuming you backup your shit).

    • oppy1984@lemdro.id
      link
      fedilink
      English
      arrow-up
      7
      ·
      4 days ago

      Steve put so much time into it too. SQRL really is the superior method of the two.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 days ago

          If SQRL was adopted, then the popular manifestations would have just as much vendor lockin, with built in password managers hosting the master private key without export option.

          Passkey is not inherently vendor lock in. It’s mostly a consequence of password managers doing software passkeys and not making it reasonable to export private keys. It does have a mechanism a site can use to lock to “trusted vendors”, but if a site does that, that is on them for being dickish.

        • Natanael@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 days ago

          Passkeys cross vendor sync is in the works right now and you can already self host with Bitwarden

      • WhyJiffie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        it does not depend on the name. like, we all use Transmission Control Protocol and HyperText Transport Protocol, and nobody cares because they don’t need to know. things can also be renamed before starting use in production, like we aren’t normally calling tech by their RFC numbers

  • DJKJuicy@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    33
    arrow-down
    5
    ·
    4 days ago

    There is still nothing better than passwords.

    I don’t want my access to be tied to a specific device. Devices get lost, or break.

    I don’t want someone to be able to use my face or finger or eyeball to access my data. You can legally be compelled to unlock a device with your biometric security.

    So current biometric security sucks. And passkeys suck.

    Also, though…passwords suck for all the reasons that we all already know.

    There has to be some better method that the owner can have full agency over, I just don’t know what. I don’t have the answers.

      • kellenoffdagrid@lemmy.zip
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 days ago

        That is a damn nice paper, thanks for sharing that! The comparison table is, if a little wacky-looking at first glance, a pretty great overview. I skimmed it for the abstract and conclusion but now I think it’s worth reading it in full.

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      2
      ·
      4 days ago

      Every attempt at using passkeys has been a step into murkier, less easily understood, less convenient security.

      Passkeys may be a “step up” from password + TFA in terms of usability, but there’s such a variety of implementations and explanations of how those implementations “keep me secure” - I feel like any idiot who grabs my phone when I’m not looking and can follow my unlock finger smudges on the screen can use my pass keys… No thanks.

    • zerofk@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 days ago

      This pretty much matches my feeling for the last 20 years or so. Passwords suck and are outdated technology. But every single alternative that has been developed over the years has sucked more, not less. They all have single-point-of-failure, vendor lock-in, assumptions about your “device”, etc.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 days ago

      Hardware security keys is the other option. The FIDO2 ones are compatible with most sites using passkeys.

  • jj4211@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    3 days ago

    One complaint I have is browser insistence that a site must have a proper certificate to work at all.

    I provide self hosted software with passkey support and probably over 90 percent of my users never set up property certificates due their private networks. So the passkey function is impossible for them.

    Which means they must use passwords. Which are far worse in this scenario. The practical risk either way is arguably low for them, but to take a more mitm/phishing resistant technique and then force it to not work because mitm or phishing might be in play…

    • setVeryLoud(true);@lemmy.ca
      link
      fedilink
      English
      arrow-up
      3
      ·
      2 days ago

      I literally just completed a Secure Code Warrior formation mandated by work, and one of the videos states “websites with expired certificates transit your information unencrypted, leaving you exposed to hackers” 🤦 like bruh you’re supposed to know better, you teach cybersecurity for fuck’s sake.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        I’ve met two sorts of dedicated cybersecurity experts:

        The sort that only understands how to click ‘scan’ in various tools and repeat output and browser error messages without understanding nuance. Had a fun incident where the nuance really mattered in interop with a popular product in my niche, company said we must not implement the interop because it was hopelessly insecure. When I pushed back on the nuance (folks behind the ‘vulnerable’ tech had way much more sway in the market than we did), got told I should really educate myself and read the paper on the vulnerability to understand that my proposol to workaround it was impossible. For one glorious moment in my career, I got to tell them to look at the paper again and specifically the author (I had written up the vulnerability in the first place). After a brief shock though, he still went back to even though I may have found it and explained in key detail, I still must not understand the implications…

        Then there’s those that understand and can engage in nuance, but will still say inaccurate stuff, because they’ve learned being accurate and precise with the lay person doesn’t work too well, and easier to just say “big scary” instead of explaining precisely the threat model and rationale. I will confess on a number of threads I have seen this happen and let it go without correction because correcting wouldn’t have changed the core of the material, but would make the discussion go on even longer and waste more time. I personally can’t bring myself to outright say the wrong things, but I do understand why it’s the more practical strategy sometimes.

        • setVeryLoud(true);@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 day ago

          I’m the kind of 'tism where I can’t get myself to tell white lies and will argue up and down until the truth prevails… sometimes to my own detriment, but I really like to understand the underlying mechanisms and the nuance underneath things, otherwise I feel lied to, and I thusly can’t get myself to feel like I am deceiving others.

          Please share the paper, I’m curious!

          • jj4211@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 day ago

            I’m trying to stay too anonymous, the paper is of super niche interest and the vulnerability comes down to a popular configuration being vulnerable, but a hardened configuration is possible, but requires randomizing some data that folks tend to leave non-random because it’s the lazier way to set that up and it wasn’t formerly recognized that the randomness of the data had security implications.

      • Kairos@lemmy.today
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        2 days ago

        Computing and by extension cybersecurity has a lot of mouth-breather idiots because it’s so new.

        • jj4211@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          It’s not so new anymore, however, it is widely known as an “easy” way to a strong six-figure salary, so we have a lot of gold-rush mouth-breather idiots that never would have gotten into this in the first place if not for the dollar signs. Really started to turn south around the time dot-com inspired early career people to get in on the bubble.

  • sunbeam60@feddit.uk
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    5
    ·
    5 days ago

    Love them.

    Using 1Password for sync.

    Never ever failed to connect to QR code passkey request, even on weird corporate networks.

    Portability has gotten so much better - there’s now a defined standard for portability that passkey providers are implementing.

    Honestly I cannot understand the criticism at all.

      • sunbeam60@feddit.uk
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        3
        ·
        edit-2
        3 days ago

        Passkeys don’t require physical storage at all. All of my passkeys are in the cloud, synced across platforms.

        • Kangae_Hishiryo@scribe.disroot.org
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          3
          ·
          4 days ago

          No, Passkeys are generated on device against a public key on the server side. If you lose the device where you created your local, private key, then you lose access to everything. Also there’s FIDO (and implementations as YubiKey and NitroKey).

          • tea@lemmy.today
            link
            fedilink
            English
            arrow-up
            13
            ·
            edit-2
            4 days ago

            This is a good encapsulation of why passkeys are having a hard time. There are so many different ways to interact and it’s confusing for the user. There are physical FIDO keys, there are keys you create per device, then there are passkeys that the “device” is a password manager like bitwarden which is cloud based and follows you from wherever. It feels like they offer very different levels of security but do not look very different to the passkey issuer.

            • Kangae_Hishiryo@scribe.disroot.org
              link
              fedilink
              English
              arrow-up
              1
              ·
              4 days ago

              Yeah, also cloud providers can easily lock-in yourself, and self host is a pain in the ass and availability with that method is a problem, especially if where you live there are problems with the power supply (even if you use battery equipment it can be a problem if you go many hours without electric service).

          • sunbeam60@feddit.uk
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            3 days ago

            That’s not how it is and not how they were designed. It was assumed from the beginning that they would live in “an ecosystem”, ie tied to secure storage and secure distribution by some system handled user side and indeed that is what phase 1 looked like: Google, Microsoft and Apple stored them on your device and replicated them across your devices. Phase 2 introduced a “interception” API so other providers could get involved easily - so providers like 1Password could rely less on browser hacks and also offer secure storage and secure distribution. Then finally, phase 3, now more or less locked down, described a portability system so that you can migrate to other ecosystems.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    English
    arrow-up
    20
    ·
    4 days ago

    I am using my password manager, which is keepass.

    I have tried adding pass keys to it, and have had mixed success. On some websites, it seems to work fine, and then on others, it seems to break miserably, and made me return back to a password.

    I like the idea of passkeys, because then you don’t have a shared secret between you and the website, and you get a different key for every single website using public-private key cryptography. That’s fantastic, but the implementation still needs some work.

    • uhmbah@lemmy.ca
      link
      fedilink
      English
      arrow-up
      7
      ·
      4 days ago

      They’re going to have to pry my keepass out of my cold, dead hands.

  • Lutra@lemmy.world
    link
    fedilink
    English
    arrow-up
    18
    arrow-down
    3
    ·
    4 days ago

    The trap: Putting any 3rd party between you and your access.
    It’s a 3 card monte game, but with security.

    Roleplay: Mr. Jonsith did you know your house is vulnerable? Your simple little key can be used by anyone to get in to your house. Security!? Our Keypass system will super secure your house. You give us your key, and when you want access, you come to one of our 5 in town locations, request access from us by showing us this new key here, and we will let you into your house.

    • adarza@lemmy.ca
      link
      fedilink
      English
      arrow-up
      5
      ·
      4 days ago

      next year: “In order to lower our costs and keep your monthly rate low, the five locations near you are being consolidated into a single location in Farawayville.”

      another year later: “In order to lower our costs and keep your monthly rate low, our physical locations are being migrated to an online presence accessible through the HahaTrickedYou app, now available in your app store.”

      seven months after that: the app doesn’t work. web site disappears. company goes under.