You’re the first person in these comments to mention 2FA with passkeys.
My gripe with passkeys is they are almost always implemented without a second factor.
You’ve mentioned the rare case of 2FA with a passkey as being a bad thing, but in my opinion those few cases are actually doing it RIGHT.
With passwords and 2FA, if someone manages to copy your primary authenticator (password) they will still be locked out because they don’t have your secondary authenticator. This protects you against malware that steals your password database.
But the way most companies implement passkeys (single auth), if someone steals your passkey database they can use it immediately. For all of the true measurable benefits that passkeys bring (not memorizable, higher entropy, automatic storage and use in a database) they are almost always used in a way that has this huge drawback: no 2FA.
This is not an issue with passkeys directly, it’s an issue with how services implement passkeys.
I think passkeys with single auth are fine because of how they end up being stored and managed.
If you use them via Windows, iOS, Android, or macOS, they are tied to the biometrics on your device. Someone has to steal your device and unlock it to get in. They have to have something you know (phone unlock password) and something you have (biometrics).
In a password manager case, trust is moved from the client device to the password manager itself. It is assumed that the password manager implements these things. For example, my 1Password needs to have both my password (something I know) and secret key or existing logged in device (effectively, something I have, as I don’t regularly type in my secret key as a password and don’t have it stored digitally except for within the password manager itself) to be logged in.
Your client device OS will not allow you to create a passkey without a local unlock PIN/password or biometric, and those local unlock methods do not traverse the Internet (they are handled with TPM/Secure Enclave).
Ah yes let’s ignore the tons of energy being used in giant data centers run by visa and Mastercard to operate the payment cards used by billions of people around the world.
“Yeah no.”
You know what happened in USA? A lot of people got their cash stolen.
Your arguments are as coherent as the dissonant “Yeah no.”
"Yeah no" have had these arguments for ages and nothing has changed.
Bitcoin uses a massive amount of energy and has neither the transaction amount, nor the transaction speed and a LOT of features missing which visa/mastercard and a normal bank provide.
Losing your wallet or purse? Cash gone.
Fraud? Yeah and now what?
Seller and buyer protection don’t exist with cash either my dude.
If you’re going to compare apples and stones at least do it honestly.
Each payment option has its own advantages and disadvantages, and it’s fantastic that we have the freedom to choose from a variety of products and services to use.
I hated it when PayPal froze my funds and wished there was an option where a middleman couldn’t decide who I am allowed to pay. Then Bitcoin came along. For me, Bitcoin works great.
For you, your method of choice works great and I’m happy for you.
Ah yes my 100.000 Euros i keep in my wallet and purse. Sure lets keep comparing apples with stones.
Yes seller and buyer protection exists with cash. I pay regularly with cash in a ot of shops.
I wouldn't mind bitcoin if it would actually do the things and has any features besides gambling. And if it wouldn't add additional strain on our planet and the future of humanity.
What do you do with bitcoin? Be honest. Gambling? Do you really have most of your assets (if you have any relevant ones) in bitcoin? Yes? No fiat besides daily use?
Did you get 'rich' from the money shifting from someone else to you?
That depends on whether the public key has been exposed.
Bitcoin addresses encode the ripemd160 hash of the public key, so by default when payments are made to new addresses they are not quantum crackable.
But when someone spends from an address they publish the public key to the chain as part of the spend. From then on, any new deposits sent to the same address are at risk of quantum attack
Suppose I make a paper wallet on an offline PC, write down the address and discard both keys. If I now send some BTC to this address, how does the client figure out the public key?
In addition to the other (great) reply pointing out the difference between 5G and 5Ghz, there is also the nuance of channels within the 5Ghz band. While the band may be lawfully used within a region, some channels within that band may be banned.
So it’s not enough to say “we have 5Ghz wifi here so it’s fine” because there are many channels within that band which may not all be treated equally.
Geography as in softwood forests, instead of the iconic maple leaf. In no way Canada would be importing 30%+ of its construction timber from the US. Canada is a major softwood timber exporter.
Value can only teleport if someone is willing to trade traditional currency in exchange on the other side. My no international fee bank account also teleports value across the globe instantly and more merchants are willing to accept it than Bitcoin.
Telll it to my friend who was escaping a country under sanctions and had to move his money elsewhere. His bank didn't have that miraculous power, but Bitcoin did.
- US Dollar: Backed by the US government, which has a monopoly on violence over its citizens and pretty much the entire world. The Federal Reserve has the ability to print new dollars as demanded by US government policies and is responsible for funding the endless conflicts that the US has been involved in overseas for the last 100 years. The inflation of the US dollar cripples the middle class and weights down future generations with debt that they will never be able to pay off.
- Bitcoin: 100% free of any kind of force, created by an individual who believed individuals should have sovereign control of their money and is 100%. Due to the limited supply cap it makes wars unfundable and actually increases in value as the years go on so you can pass it on to your children and their children.
Even as someone who thinks crypto is an absolute cesspool, and while acknowledging that even in the "move cash" scenario that the vast majority of it is shady, from avoiding taxes to ... whatever, to be honest, I can't get too mad if it helps the "average person" who is sincerely escaping a "problematic" country/home do so.
> Value can only teleport if someone is willing to trade traditional currency in exchange on the other side.
If no one paid traditional money to your friend on the other side, he’d have no money. Also, whoever was sanctioning the country, can also very well sanction and seize the bitcoin if they’d like.
Your "no international fee bank account" also inflates away at 8-10% a year if you're holding US dollars in savings. And about the same or more for other currencies.
The Federal reserve has printed 1/2 of all dollars in existance in the last 6 years, and deflated the value of your dollar by around half.
While I can buy a cup of coffee with bitcoin, I'd rather use the federal reserve notes that are backed by nothing but empty promises from government institutions that look down on you.
Bitcoin is down 15% after being up 10,000% in the last decade... while the dollar is worth 50% of what it was 5 years ago.
If you bought bitcoin at $10 or even $1000, what do you care if it drops down to $60k for a week?
The world must be very confusing when your time preference and economic scope is 1 weeks worth of data.
My gripe with passkeys is they are almost always implemented without a second factor.
You’ve mentioned the rare case of 2FA with a passkey as being a bad thing, but in my opinion those few cases are actually doing it RIGHT.
With passwords and 2FA, if someone manages to copy your primary authenticator (password) they will still be locked out because they don’t have your secondary authenticator. This protects you against malware that steals your password database.
But the way most companies implement passkeys (single auth), if someone steals your passkey database they can use it immediately. For all of the true measurable benefits that passkeys bring (not memorizable, higher entropy, automatic storage and use in a database) they are almost always used in a way that has this huge drawback: no 2FA.
This is not an issue with passkeys directly, it’s an issue with how services implement passkeys.
reply