Tag: #security (2 posts)


How I'm using Password Managers

Passwords are hard. Yet, they are the one authentication mechanism supported by every service we’re using. Sometimes even the only one. Since they are so difficult to avoid, we need a strategy to cope with them. Let me show you mine.

The ideal password

The ideal password fulfills the following criteria:

  1. It’s used only for one account.
  2. It’s random and long enough to make brute-forcing impossible.
  3. It’s not stored unencrypted in a file.

So we have to create a long, random password for each website and remember it. That’s impossible.

How I Switched to Passkeys

It’s 2025 and the Shai-hulud supply chain attacks are rolling over the npm ecosystem. It’s a wake-up call. The worm exposes how poorly many developers handle security. I too work with npm on a daily basis. I too use insecure practices all over my digital life. I’ve been thinking about improving matters since a while. Shai-Hulud was the last thing it needed to finally get me to take action.

What are Passkeys?

Passkeys are hardware security tokens that follow the FIDO2 / Webauthn standard. The come in the form of tiny USB-sticks with a button.