Comment by max_
2 years ago
The problem is key management & key storage.
Smartphones & computers are a joke from a security standpoint.
The closest solution to this problem has been what people in the crypto community have done with seed phrases & hardware wallets. But this is still too psychologically taxing for the masses.
Untill that problem of intuitive, simple & secure key management is solved. Cryptography as a general tool for personal authentication will not be practical.
> But this is still too psychologically taxing for the masses.
Literally requires the exact same cognitive load as using keys to start your car. The problem is that so many people got comfortable delegating all their financial and data risk to third parties, and those third parties aren't excited about giving up that power.
>> Literally requires the exact same cognitive load as using keys to start your car. The problem is that so many people got comfortable delegating all their financial and data risk to third parties, and those third parties aren't excited about giving up that power.
This perfectly describes the current situation with passkeys.
Passkeys are a great idea--they are like difficult, if not impossible-to-guess passwords generated for you and stored in a given implementor's system (Apple, Google, your password manager, etc.).
Until passkey systems support key export and import, I predict that they will see limited use.
Who wants to trust your passkeys to a big corporation or third party? Vendor lock-in is a huge issue that cannot be overlooked.
Let me generate, store, and backup MY passkeys where I want them.
That doesn't solve the general "I don't want to have to manage my keys" attitude that some people have, but it prevents vendor lock-in.
Why export/import? Just create new passkeys on whatever device or service you want, and register those as well. OR just use a yubikey, put it on your keyring, and use it to log into everything.
Most crypto wallets do have import/export enabled though, so if you're logging in with a web3 identity, everything should just work.
2 replies →
> The problem is that so many people got comfortable delegating all their financial and data risk to third parties
The "problem" is that most people prefer to not lose their life savings because their cat stole a little piece of metal and dropped it in the forest.
Yup, and some people crash their cars, and some people accidentally burn their own house down. Most people have figured out how to deal with situations like what you mention. People who have trouble following best practices are going to have a hard time, but that's no different than status quo.
4 replies →
I mean my Yubikey is really easy to use, on computers and with my phone. Any broad change like this is going to require an adoption phase but I think its do-able.
I wouldn't be surprised if things got so bad that people would get used to the rough edges as the alternative is worse.