Light

Episode #972 Quiz

Passkeys: A Shattered Dream?
Date: 2024-04-30 | Length: 2 hrs | Episode page at twit.tv

About this episode

The UK’s PSTI law now mandates secure consumer IoT baselines: no universal default passwords, vulnerability-reporting contacts, disclosed update support periods, authenticated update channels, anti-rollback, secure storage, minimized attack surfaces, integrity checks, telemetry review, data deletion, and resilience. Passkeys are criticized for vendor lock-in, broken attestation, storage limits, and fragile, opaque portability.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what did the UK PSTI law require manufacturers to state for consumer smart devices at the point of sale or sale-facing materials?
Question 2: In Steve's summary of the baseline requirements document, what did the law say about brute-force resistance for devices that are not constrained devices?
Question 3: What did the episode say about how pre-installed unique-per-device passwords must be generated?
Question 4: Why did William Brown say Chrome's failure to implement the Authenticator Selection Extension mattered for WebAuthn deployments?
Question 5: According to William Brown's critique as summarized in the episode, what is one practical effect of treating Passkeys as resident keys?
Cancel