ユーザーデータの暗号化にパスキーを使用するのはやめてください
本文の状態
日本語全文を表示中
詳細モードで約1分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Simon Willison Blog
Tim Cappalli氏は、ユーザーがパスキーを頻繁に紛失し、データが回復不能になるリスクがあるため、業界にパスキーによるユーザーデータ暗号化の使用停止を訴えている。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
ユーザーデータの暗号化にパスキーを使用することを、どうかやめてください
ユーザーは頻繁にパスキーを紛失するためです。また、自分のデータがそれらを用いて不可逆的に暗号化され、もはや復元できないという事実を理解していない可能性もあります。
ティム・カッパリ:
より広いアイデンティティ業界の皆様へ:*ユーザーデータの暗号化にパスキーを使用し、推奨することをやめてください。お願いです。彼らを優れたフィッシング耐性認証資格として機能させることに集中してください*。
Via lobste.rs
原文を表示
Please, please, please stop using passkeys for encrypting user data
Because users lose their passkeys *all the time*, and may not understand that their data has been irreversibly encrypted using them and can no longer be recovered.
Tim Cappalli:
To the wider identity industry: please stop promoting and using passkeys to encrypt user data. I’m begging you. Let them be great, phishing-resistant authentication credentials.
Via lobste.rs
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み