Before you continue

@thelinuxEXP Tip about banking app. I like #wise. It works really well in browser with #yubikey #passkey holder.
Android: Google vereinfacht sicheren Transfer von Passkeys und Passwörtern | heise online
https://heise.de/-11315823 #Android #Passkey #Passwort

🚨 NEWS: Cybersecurity per Sviluppatori Web: Guida Definitiva a OWASP, Autenticazione Moderna e Prevenzione Vulnerabilità in Laravel

Ecco i punti chiave in breve:
💡 Ogni sviluppatore web, indipendentemente dal framework o linguaggio utilizzato, si trova a dover fronteggiare minacce informatiche in continua evoluzione. Ignorare la sicurezza non è più un'opzione: u...

🚀 LINK: https://meteoraweb.com/sicurezza-informatica/cybersecurity-per-sviluppatori-web-guida-definitiva-a-owasp-autenticazione-moderna-e-prevenzione-vulnerabilita-in-laravel

#oWASPTop10 #webAuthn #passkey #laravelSecurity #sQLInjection

One for the #passkey hall of shame.

I don't have 1Password completely set up on this computer (though I have the browser plugin from an earlier job) and so after logging in to PayPal I am just ... stuck? I can't proceed with creating a passkey, nor skip it.

Wrote up the test procedure for this. And another experience that's bugging me.

#passkey 's are a good concept, but #Microsoft is not impressing me right now.
https://webapps.stackexchange.com/questions/182396/if-you-use-a-passkey-to-sign-in-does-microsoft-still-ask-for-a-verification-code/

If you use a passkey to sign in, does Microsoft still ask for a verification code?

If you have a passkey for your Microsoft account, does it avoid needing a verification code? There is a "Sign-in options" button, on the page you enter your email to sign in. In the sign...

Web Applications Stack Exchange
Microsoft va arrêter les codes par SMS pour les connexions aux comptes personnels !

Microsoft veut mettre fin aux codes de validation envoyés par SMS pour la connexion aux comptes Microsoft. A la place, des passkeys seront utilisées.

IT-Connect
Microsoft 淘汰短訊驗證碼 全面推動 Passkey 無密碼登入
Microsoft 宣佈將分階段停止向個人帳戶發送短訊驗證碼,改用 Passkey 通行密鑰、已驗證備用電郵及 […]
#科技新聞 #Windows 11 #資訊保安 #microsoft
https://unwire.hk/2026/05/20/microsoft-passkey-sms-verification-end/fun-tech/?utm_source=rss&utm_medium=rss&utm_campaign=microsoft-passkey-sms-verification-end

Did some reading about #WebAuthn / #Passkey.

The specs and promotional materials make much ado of hardware tokens, TPMs, and smartphones, but completely fail to mention how this might be used with software password managers like #KeePass / #KeePassXC.

Hardware tokens are great in corporate environments but horrible otherwise because you can't back them up.

TPMs and smartphones are notoriously insecure. Storing secrets on them is laughable.

#security #cybersecurity #infosec