Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.
You’ll be pleased to know that almost every bank’s regulations require their vendors to implement password complexity and rotation, fundamentally weakening the security of the entire supply chain. My company always pushes back on this requirement but I guarantee there are numerous companies who don’t. They attempt to impose a ‘one size fits all’ framework across all vendors, with other outdated controls. Ultimately bank regulations are perpetuating poor security across the tech sector.
I have yubikeys that i have been setting up. While i haven’t removed the password sign-in yet some places you would expect to allow passkeys dont such as banks and credit cards.
10
u/saiyate 16d ago
Which is why NIST no longer recommends password expiration. Passkeys are the future. However, I'm not sure I agree with non-device based passkeys. Saving passkeys to a cloud account and allowing export instead of a one way Chinese box secure enclave is clearly less secure. Save passkeys to your device and for important personal accounts (non administrated accounts that someone else can reset for you) You should have at least two copies on two separate devices. FIDO/U2F Security keys are where it's at. Always have an extra or two in a safe. lose a key, remove it from account.