Posted by ColinWright 6/30/2025
Wonderful. The Remote Code Executor now takes care of your pass.... too. What can go wrong ?
One thing browsers are recognized for, it is their security record. /s
Also, Apple requires at least one AppleID password, that I need to keep entering at random intervals - usually when I update any device, but sometimes randomly when I buy stuff on App Store.
Also I still need a Mac user password, which is a different password, of course.
Why “of course”? No one is stopping you from using the same password there. Also, you can optionally turn on the option to be able to reset your Mac’s password with your Apple Account password.
(There is also an Apple Recovery password, but that's for encrypted recovery, a different thing, but that is very hidden and experimental.)
Username/password is much easier to grok (for developers and users) and while it absolutely has downsides, as a user, I can fully protect myself with username/password (unique password per site).
Passkeys might allow for fewer _user_ footguns but I worry there more _developer_ footguns. Also as a “power user”, I don’t want to deal with passkeys when I’m trying to automate something or scape my own data out of a website. It’s just another complication and I worry that anything edge-case-y (even approved methods) will break or have complications if you use passkeys (think app-specific-passwords when 2FA rolled out for gmail access).
Because of this I consistently decline passkey usage until such a time that I feel it’s better understood by the people implementing it.
You can stop supporting new ones, but as soon as you destroy old ones YOU are a vulnerability, Microsoft.
How can I ever trust you to not delete secrets in future?
https://support.microsoft.com/en-us/account-billing/changes-...