• xylogx@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    It is hard to do well which is why I worry. Google probably has the best overall account security, you could fo worse than modeling after them.

    The short answer to your question is Passkeys. But you need a whole system of account recovery around them.

    • CubitOom@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      11
      ·
      2 days ago

      Oh, you can easily bypass passkeys with automation. Don’t even need an image recognition model, just a QR-code scanner like zbarimg.

      But i never tried googles passkey feature since it never seemed as secure as a 48 char computer generated password. So I’m not sure exactly how it works.