this post was submitted on 26 Sep 2026
411 points (95.2% liked)

Technology

88559 readers
3339 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] GreenShimada@lemmy.world -2 points 1 week ago (4 children)

Passkeys are worthless trash, invented explicitly to save Microsoft and Google money on password reset server time.

They do not solve session hijacking. Any attacker that has your granny on the phone to read them her password can also tell granny to go to a link and give them her session cookies.

[–] sunbeam60@feddit.uk 17 points 1 week ago (2 children)

You think big tech did this to save… on … CPU costs of password resets?

This is actually really what you think?

[–] GreenShimada@lemmy.world 1 points 4 days ago

Not CPU costs, processing costs. Password resets are actually quite expensive. Microsoft and Google pushed the FIDO Alliance toward widespread use of a passwordless login credential because it benefited them. Google and MS get tens of millions of password resets a year. So if each one of those cost them $2 (some companies spend as much as $70 on each one if a human is involved), that's literally tens of millions of dollars saved. Then you say "oh, for security" as the tie-in to not make it about your bottom line.

https://www.authx.com/blog/how-much-does-a-password-reset-cost/ https://journal.jadaptive.com/the-true-cost-of-password-resets/ https://www.m365.fm/passwords-are-broken-passkeys-fix-everything/

[–] TrumpetX@programming.dev 6 points 1 week ago (1 children)

Not the commenter, but they're not taking about CPU costs.

[–] sunbeam60@feddit.uk 5 points 1 week ago (1 children)

Fair, but costs of resets overall. This is not a factor in tech giant costs.

[–] TrumpetX@programming.dev 5 points 1 week ago* (last edited 1 week ago)

You world be very surprised. It's not what I directly work on, but there are entire programs dedicated to tracking and lowering the cost of password and account resets (and doing it securely). That last part is the hard thing. Large organizations can save millions of dollars if they can get people to not lose/forget their credentials -or- self service those resets (but even then, having that person do it is now losing their time and energy).

It's not just indirect opportunity costs either, it's direct costs to the IT organization. Smaller teams can absorb this stuff as a rounding error on their time, but the second you're counting in the thousands, you need to deal with this type of thing. (And I'll repeat: securely)

Now imagine doing it as a B2C+B2B organization like Google or Microsoft. The costs are staggering.

[–] Evil_Incarnate@sopuli.xyz 13 points 1 week ago

Grannies love to hand out cookies.

[–] im_fine_sandy@nord.pub 8 points 1 week ago

They solve the problem of people using the same password everywhere. That's significant.

[–] Technus@lemmy.zip -4 points 1 week ago (1 children)

That's what CSRF mitigations are for.

Do you actually understand how any of the modern web works or does your knowledge stop at W3Schools tutorials from the mid-2000s?

[–] GreenShimada@lemmy.world 1 points 4 days ago

No, sorry, I'm a network vegan. I only eat things that are grown at Layer 1. My packets are whole-grain and processed by hand. carried by pigeons. IP by Bird is how I surf the web, dude!