In practice, operationally, none of this is solved. Every website/app/platform handles logins differently. Some are still doing SMS 2FA, some still do passwords, some implemented passkeys in the wrong way, some are doing app based MFA, some are doing magic links, some are doing email codes.
You can't in good faith say this is "solved" when it's just more complicated than ever, and the UX is terrible (passkeys, cough)
patja•20m ago
The article has quite a bit of "me, me, me, I, I, I" self-promotional content. Which makes sense given it is an advertisement for his book.
I find it jarring to hear that authentication is "largely solved" by passkeys and FIDO, technology that a very very small minority of applications support. Making claims like this combined with the focus on self-promotion is a quick path to being dismissed and ignored.
robalfonso•1m ago
Agreed, this is like the lead the horse to water issue. Yes the water exists, no one is really drinking it yet.
andychiare•24m ago
Authorization has always been the primary question; authentication is simply an ancillary question to help answer it.
VCFundedGenYer•25m ago
In practice, operationally, none of this is solved. Every website/app/platform handles logins differently. Some are still doing SMS 2FA, some still do passwords, some implemented passkeys in the wrong way, some are doing app based MFA, some are doing magic links, some are doing email codes.
You can't in good faith say this is "solved" when it's just more complicated than ever, and the UX is terrible (passkeys, cough)
patja•20m ago
I find it jarring to hear that authentication is "largely solved" by passkeys and FIDO, technology that a very very small minority of applications support. Making claims like this combined with the focus on self-promotion is a quick path to being dismissed and ignored.
robalfonso•1m ago