As much as you're right, the attitude in most software development is not "lets make this as secure as reasonable," it is "lets make this barely functional and then move onto the next thing."
My current phone is definitely flagship for the time, ~$850, and I will be holding onto it as long as I can because flagships, with headphone jacks, available in the US, are something that just does not exist anymore, and I'm not spending $1500+ to import the cheapest Xperia only to have it barely work on my cell network.
I think that last thing is key. The authors of these things published them with the express intent that other people would read them. Not that they would be used as training data.
Sign in with a QR code is dangerous though because at that point theres very little stopping QR phishing and forwarding the bluetooth request to your browser. See the most common Discord scam.
> forwarding the bluetooth request to your browser.
This isn't a thing. Discord's QR Code scanning is entirely a feature they made unrelated to passkeys or bluetooth. Passkey auth using a QR code has a step that verifies the proximity of both devices using BLE.
Amazon does benefit from increased account security; they don't have to refund non-fraudulent orders after all. For most people, a passkey is genuinely more secure.
I don't like passkeys either (I use a password manager anyway, and long secure unique passwords), but I understand the need. But yeah it really annoys me when every website wants to give me a passkey, or wants me to use a passkey, instead of just taking me to a page where I can enter my novel-length password.
reply