• Specal@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    6
    ·
    10 months ago

    Alot of people don’t like Microsoft, but they’re pushing for zero password authentication for a reason. Passwords are getting really insecure really fast.

      • Specal@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 months ago

        I just use their Authenticator app out of convenience, I get a notification when I login through it and it asks me to input the correct number given by the app, a 2 digit number.

      • Flying_Hellfish@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 months ago

        Not entirely, but now MS, and a lot of other companies, are pushing passkeys. I still prefer password + hardware 2fa but it’s safer than people reusing the same password everywhere.

        • Encrypt-Keeper@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          9 months ago

          I am a fan of passkeys. Particularly because they essentially function as hardware 2fa, except they’re the only factor, which isn’t as big of a problem because it’s not something you can steal in a service breach like passwords. I’ve also noticed that even when using passkeys, most sites let you force a TOTP code as well anyway.

          • Flying_Hellfish@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            9 months ago

            Very true, the big issue with them is a lot of popular hardware keys, including the yubikeys that I have, are limited to the number passkeys they can store (yubikey is 25 unique). Luckily password managers are starting to support them, but now you’re back to having a strong password + hardware 2FA to store those passkeys anyway.

            I do like TOTP or just hardware 2FA as a backup for my passkeys. What I really can’t stand is sties that only offer SMS as 2FA, it makes me more angry than it probably should.

            • Encrypt-Keeper@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              9 months ago

              iPhones natively support passkeys, so at the very least the iOS user base can easily use them. Not sure about Android though.

    • CubitOom@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 months ago

      How does Microsoft’s implementation work?

      Is it possible to log into windows without a Microsoft account using that method?