

Biometrics are NOT shit.
And the recovery process is useless if you don’g have acess to your recovery method. Passkeys create the Ouroboros kind of situation.
[ Cisheterosexual | Cisgender | He/Him | 24 yo | ES/EN | Venezuelan | ADHD, autism and bipolar disorder | agnostic atheist ]
I’m just a random weeb. I love anime, dubstep, science, philosophy, logic and tech all along.
PS: English isn’t my native language, so sorry if I mispell some things, please kindly point it to me.


Biometrics are NOT shit.
And the recovery process is useless if you don’g have acess to your recovery method. Passkeys create the Ouroboros kind of situation.


Yeah, also cloud providers can easily lock-in yourself, and self host is a pain in the ass and availability with that method is a problem, especially if where you live there are problems with the power supply (even if you use battery equipment it can be a problem if you go many hours without electric service).


Download statistics for every app (which is neat because that can indirectly tell me how good is an app), also it shows the reproducible builds’ status for every app, allows you to directly scan an app through Exodus so you can have a detailed view of its possible trackers, also it lets you blocklist apps (althought I’d love it to let me blocklist authors too, and the UX is a bit slow for now as it requires you to go throught the settings to be able to do it), the y have a reasonably big amount of preconfigured repos and make the process of adding new repos way easier than other clients, their UI is just beautiful and now they made it hugely customizable, and they have so many QOL features that’s a breeze to use.


Honestly idk, but I hope they’d were.


For some people that really need that, even less than one dollar is too much. $20 is basically matter of life or death.


The main problem is if that you lose the device that’s physically attached to the passkey… You’ll lose your account.
I’d just prefer a biometrics-first approach.
Unless hackers started cutting people’s fingers, which is something just too risky for a rational hacker to do so it’s more than improbable, biometrics are way more secure, consistent, battle-tested and most important, more convenient and, by design, unforgettable.


No, Passkeys are generated on device against a public key on the server side. If you lose the device where you created your local, private key, then you lose access to everything. Also there’s FIDO (and implementations as YubiKey and NitroKey).


Looks at the 99% who can’t afford a VPS
You’re forgetting the most important thing


Laughs in RPN


But even if so, they ban you from the official server when you use some client as Molly or Flare. It’s pretty useless then to use them if you’ll have to self host, something that for Signal is pure cancer, thus in practice that’s equivalent to banning third party clients.


Based.
“Nooo, but XMMP and Matrix can be so hard for normies”
Ewww… Not actually, that’s only if the client has a horrible UX, but Conversations and Cheogram for XMPP and idk, Extera Next or Sable Next for Matrix are pretty straightforward for that.


Other P2P networks too.
Long live to Soulseek, eMule/ed2k, IPFS, Iroh, Retroshare, Tox and the like.


You thought I was the Great China’s Firewall but it was me, the Tiny USA’s Waterwall!


That’s fair.
Although reproducible builds are something I truly love because these make auditing so much easy.


Lmao, it can be achieved in better ways; they can just use a ZKP FLOSS captcha (such as Anubis, but adapted for native apps, there are some), or manual verification (such as most XMPP or Matrix instances, and even more general online services providers such as Disroot [this one uses Anubis AND manual email verification for the signup process, then only Anubis]).
They’re shady asf, and now are being exclusionary towards these who can’t pay? Hell naw, fuck 'em


I don’t get why the fuck are you getting downvoted if you’re saying the actual and only truth.
They have a centralized infrastructure, need lots of permissions that are unnecesary for an app like that, require you to use a phone unless you pay, and, exactly as WhatsApp (and, surprisingly, unlike Telegram), they don’t want unofficial clients because that way they’ll lose control, while using paternalistic “it’s for your security” arguments. They’re just a wolf disguised as a sheep.


Also, is that supposedly ZKP payment method something verified, audited and, more important, open sourced? It’s Google, so I’m 101% that no.


If they pass through Google infrastructure, then it’s a no.
Also, why would you have to pay for something that should be a completely free and basic feature?
They’re completely off the rails.


Yeah, but this one’s better: •
!!!
Lmao, easy to steal.
What’s going the hacker to do? Cut off your fingers or extract your eyeballs? 🤣🤣🤣🤣