Hacker News new | past | comments | ask | show | jobs | submit login

Blogspam for https://www.microsoft.com/en-us/security/blog/2024/12/12/con...

The title is inaccurate. Microsoft doesn't actually "confirm password deletion for 1B users". They confirm it for millions. They have a concept of a plan for getting >billion people on passkeys as an auth factor, and will be able to get some of them to go passkey-only.






> Our experiments show that people love passkeys and are ready for them.

Really? I somehow doubt that.

> If they don’t enroll when you first ask, don’t assume their decision is permanent

No is supposed to mean no


I don't mind passkeys and Bitwarden will take care of them for me. I enrolled most important stuff with hardware tokens and it's the same services now offering passkeys so I haven't migrated but probably eventually will.

Microsoft only started supporting webauthn in the last couple years so it's surprising they're actually rolling out passkeys. Maybe they finally gave up on smart cards


Do you run your own Bitwarden server? If so are there any issues you've come across?

They are really good. And but my android phone (on android 13) doesn't support it. So what should I do? Buy another phone?

> No is supposed to mean no

One counterargument is that nobody forces you to use their services.

I think the root problem is that nobody produces personal hardware over which the average person could conveivably assume full control. I'm not even sure it's possible, given how advanced the computer technology is.


> One counterargument is that nobody forces you to use their services.

Not specifically Microsoft, but more and more government services are accessible only through apps that are only offered through Apple's App Store or Google's Play Store. (Either directly, or because a generically eID app is used.) So in this case, I am absolutely forced to agree to either Apple's or Google's ToS to interact with my government.


I'm assuming those applications are hardcoded to use either Apple or Google (respectively) as the passkey service provider? IE. that the problem is that they don't allow you to configure your own 3rd party passkey service?

no you are seeing the easy ramp access pushed on you.. government is unique (in the USA) that it is required by law to be accessible to citizens including disability etc.. you can do almost anything using some (terrible,slow,error filled) paper process IMHO .. and there is a systemic reason why this will remain true, even as they push "one phone,one person" dystopia

There are other countries

No one is holding a gun to your head, no. But ij a lot of ways, you are required to use these services to participate in society.

My job forces me to use Google and Microsoft because that's what the entire industry is built on. Should I uproot my entire family's lives so I can move across state to find a new job? Is that a reasonable compromise to make so I don't have to complain about windows?


Er, isn't it a bit manipulative to equate changing a software system with the more serious uses of that phrase?

It is manipulative to constantly harass users with 'prompts' until they break down and give up.

Indeed. My biggest bugbear with this is google's "location accuracy" service, which implicitly sends them not only your location, but a detailed map of any networks around you. It takes active effort to keep it turned off (and doing so actually breaks quite a few UI flows in google maps!), and still I've accidentally turned it on a few times and only noticed because I actively check for it. There is no reasonable definition of 'consent' which can be derived from that setting.

> It is manipulative to constantly harass users with 'prompts' until they break down and give up.

"If it works for Google, it shall also work for us". Regards, Microsoft /s


No, it's exactly the same tactic that sexual predators use. Nag and whine and wear down the target until they agree to make you shut up.

It's predatory behavior pure and simple. Call it what it is and stop apologizing for abusers.


I never took that phrase to be reserved for sexual situations - in fact my mom used to use it with me all the time over toys, ice cream, etc. "Come ON, PLEEEASE?!" "No means no..."

I think it's a phrase that is often applied in sexual situations, but not intended to be exclusive to them.


I just had a great, novel business idea. I'm going to start writing brief, ad-laden, content-free articles all about someone else's blog post. Glad I thought of that before anyone else did. Please don't steal my idea.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: