A lot of people in security circles seem to place heavy emphasis on authenticators:
Passwords!
Strong passwords!
Passkeys!
Multifactor auth!
Security dongles!
Biometrics!
Passkeys in dongles!
Passkeys in dongles protected by biometrics *and* passwords!
etc.
Meanwhile the average user will happily click on that big button labeled "I forgot my password" and get credentials delivered straight into their mail inbox...
Not faulting anyone for this but I feel like there's a huge disconnect happening here :02lurk: