SShortSingh.
Back to feed

Passkeys Offer Phishing-Resistant Security Through Unique Key Pairs

0
·2 views

A passkey is a unique cryptographic key pair that a user's device generates for each specific website, with only the public key stored by the server. This design prevents phishing attacks because a signature created during login includes the website's origin, making it invalid for fraudulent look-alike domains. Industry data shows passkeys have significantly higher successful sign-in rates compared to traditional passwords. However, the core security feature that blocks phishing also means the private keys are designed to be non-exportable by default, though cross-platform transfer protocols are under development.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Hermes AI introduces secure framework for packaging and distributing custom AI agents

Hermes AI has launched Profile Distributions, a framework for packaging custom AI agents into version-controlled repositories. The system bundles an agent's identity, skills, and configuration files while separating authored instructions from user-owned runtime data. Developers can distribute agents via Git repositories while preventing exposure of private keys or session memories through enforced .gitignore rules. Users install agents locally using the Hermes CLI, creating isolated environments without accessing private memory stores. The framework aims to provide a secure alternative to sharing unstructured YAML files or system prompts.

0
ProgrammingDEV Community ·

Apple HomePod Mini Cam reportedly ships with firmware kill-switch disabling lens

Reports indicate Apple's upcoming HomePod Mini Cam may ship with a firmware-controlled kill-switch that disables the camera sensor by default. This feature would allow users to verify and control the camera's active state through HomeKit commands. The device reportedly maintains other functions like audio, temperature sensing, and motion detection even with the camera disabled. Apple's approach offers privacy by default, differing from continuous recording models used by competitors.

0
ProgrammingDEV Community ·

Apple launches HomeKit camera with video disabled by default for privacy

Apple has introduced a new AHC-01 HomeKit camera that ships with its video recording feature disabled. The company's stated goal is to provide default privacy, reduce energy consumption by approximately 40%, and minimize security vulnerabilities. The hardware includes a video encoding chip, but it is locked at the firmware level until a user manually enables it via the Home app or command-line tools. Activating video recording may have legal implications, as continuous recording without explicit consent can violate regulations like the GDPR in the EU and CCPA in parts of the US.

0
ProgrammingDEV Community ·

Git 3.0 to default to SHA-256 hashes, requiring tooling audits

The upcoming Git 3.0 release will change the default object format from SHA-1 to SHA-256. This will increase the length of a full commit hash from 40 to 64 hexadecimal characters. Many existing tools, such as CI scripts, database schemas, and internal APIs, may fail because they hardcode assumptions about the 40-character hash length. Developers are advised to audit their systems using SHA-256 test repositories to identify potential breakages before the update.