Trollface

codeberg: https://codeberg.org/asudox

aspe:keyoxide.org:D63IYCGSU4XXB5JSCBBHXXFEHQ

  • 0 Posts
  • 27 Comments
Joined 6 months ago
cake
Cake day: April 28th, 2024

help-circle
  • Passkeys are only good if they aren’t in a online password manager. They are better than TOTP 2FA in terms of security and phishing resistance. I see 2FA as a last resort when someone even gets into my password manager. Storing passkeys completely make this useless, as I’m sure anyone that can log into my accounts would’ve done so by getting a hold of my unencrypted password manager database. Unless android provides a real offline way of storing passkeys in the device, I am not interested alot.









  • Point 2… if you pay for a email aliasing service, you will be locked in. What I suggest is using plus addressing. e.g.

    example+83hdo72@example.com
    

    As long as you keep using randomized ones, this’ll be as good as an alias against automated and manual login attempts. It just does not hide your base email, which would be

    example@example.com
    

    Many email services offer some free aliases. For example, I use one alias, along with my main email that is only used for important services. Other than that, I have an alias that is used for online accounts. This way, your main inbox is free of spammers. And even if your main address were to be the target of a spammer, the automatic spamming software most likely will not chop off the plus part, so you can easily block that email with the specific plus identifier. Not as good as external email aliasing services, but at least you won’t be locked into the email aliasing service. Bitwarden has a generator for such things, really nice tbh.