Microsoft is making Windows passwordless
theverge.com
theverge.com
All bad ideas imho. How is a pin different than a password? "face authentication" has never been accurate for people of color afaik. I cant stand Win10, forced to use it at work but I will never use it for any of my personal computers until they remove the phone-home-back-door-ability and the many more dumb and silly features.
Worst part is, I recently installed Windows and it FORCED me to use a PIN until I finished setup and went back into the settings to disable it.
Why does Microsoft think passwords and consumer choice are going out of style?
Edit: to me it seems like microsoft is using a password for their cloud account, and a rebranded password for offline access.
It changes the threat model from "knows password" to "knows PIN and has physical access to user's device".
ETA: Something the article should probably have better underscored was Microsoft was specifically talking about "Windows Hello" PIN entry rather than PIN usage in general.
(Also, it doesn't have to be a PIN, it can be biometrics if you prefer.)
That is, the user has a very limited number of tries after which, only the password will unlock it.
Then of course, great care must be taken to disallow resetting those number of tries.
(Same for Windows Hello whether faceprint or thumbprint or what have you: the biometrics just unlock the local TPM key, they are never shared outside of that device and its relationship with the local TPM.)
Because the prevailing wisdom of the current tech industry is that users are cattle to be farmed?
Good question. I wondered the same when I noticed you can enable using an "alphanumeric pin" which happens to be the same as your password.