Yeah this is my situation. My personal computer is really infrequently used and as such I’m already in a dangerous situation when it comes to sign-in risk detection kicking off and asking for further authn proofs. I’ve had my phone die (and come to life when its replacement arrived) and that was a harrowing situation because all the MFA is stored there. Passkeys seem to make it worse, unless I subscribe to a sync service, which I need to infallibly trust (and I’m iffy on that; 1Password has a good security model and all that but passkeys are a different level of trust).
They’re device-bound certificate based authentication with some shiny bits.
Or they’re portable-via-certain-services certificate based authentication with some shiny bits.
Either way they’re new and try explaining that the user needs a new one for every device (or needs a new app to carry them around in) and that if the device dies, or the app dies, they lose it all. I have quite a few people in my life who can’t wrap their heads around using a password manager.
Personally, I find them irritating. My chosen password manager on iPhone doesn’t support them, so I need to have the iOS password vault turned on (yes, this is a dark pattern Apple has created to try to increase adoption of their password vault) to use them. Adoption needs to be much higher, interoperability needs to be better, and they need to put back the hint for which vault to use (which was removed early on to keep Microsoft and google from forcing chrome/edge vaults, but has the actual effect that chrome/edge tend to win the race over other options and means that the passkey prompt might be for a different app than the one that you prefer, leading to further user confusion)
How many unemployed people do you know in the trade? You can’t learn it overnight. Existing projects are underway, and the equipment needs to be built.
Edit - reread the summary there and they broke ground in 2019; you’re right that’s silly.
The article is about Southwest Airlines. Maybe a bad copy/paste?
the Louvre spent more money on acquiring expensive art that upgrading its security.
Arguably that’s what the Louvre’s business is. I’d argue they need to work on their security, but as we in the industry all know, failing a regulatory requirement, getting more budget can be quite an uphill battle.
This from a 11 year old security audit has nothing to do with the recent heist other than demonstrate that at the time of the audit they didn’t have the funding to hire good information security people.
Conversely, when an engineer or engineering manager repeatedly raises an issue and is told that they need to make it work by a date or there’s hell to pay, there’s no point in having the skip level conversations. The engineers just leave.
This is why unions matter. Aside from negotiating employment agreements, they can lobby government. Enough unions across enough industries will make change.
I just saw that tinder is testinf ai to match profiles.