>This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport).
Ok but how do I share my Netflix or Spotify accounts for example with those?
>This is solved by passkey-implementing software and devices (with Bluetooth) allowing you to log in with a QR code (Webauthn via CTAP hybrid transport).
Ok but how do I share my Netflix or Spotify accounts for example with those?
The same way you share them now: sharing the account name and password and doing whatever you currently do to deal with any 2FA they occasionally toss in.
If they also allow passkeys as an alternative form of login that doesn't need 2FA you can use those to make the account sharing more secure.
When setting up sharing with someone first change the password to something else, and then share the account name and password. After they log in the can add a passkey to the account on their device or devices.
Then you can change the password back to your real password. When they want to use the account they login with their passkey.
If the service doesn't accept login passkeys but does allows passkeys for 2FA, you have to use real password sharing, but at least they can have a passkey for 2FA which may be easier than how you know handle 2FA.
How do people handle 2FA with account sharing? If the site uses TOTP you can give them the QR code that you received back when you made the account (you do save a screenshot of such QR codes for backup, right?).
But how do you handle SMS 2FA, which seems to be far more commonly offered than TOTP?
For email 2FA I suppose you could set up a filter on your incoming mail that forwards any incoming code emails to the people you shared with, and hope that the time limit on the code is long enough for this to work.
2FA is lowkey designed to reduce paid account sharing. It's always those services that are so eager to get people 2FA'd. Microsoft Minecraft account is the hardest thing to log into, and they even perma locked tons of people out.
Can't you just share the TOTP secret key?
TOTP is unfamiliar or hard to use for most people, so they use SMS. Most sites don't support TOTP either.
Even if you use TOTP, it's not designed to be shared, for example look up what hoops you need to jump through to export a single TOTP code in Google Authenticator. And they used to not even have that option; they told you to set up multiple TOTP codes on each website instead. Even on 1password I had to look up a tutorial on how to import a TOTP code cause the menu is in a very non-obvious and deep spot.
I've shared with non-tech people a few accesses with TOTP codes and it's just a WhatsApp message away "hey dad, enter 12345 when asked".
Code is different from key. The secret key is how he can get new codes without you having to deal with it every time he logs in.
In general you shouldn’t - Netflix[0] really should get proper invite-based family sharing, and Spotify’s subscriber agreement has a section that defines Premium as a “Single-user Paid Subscription” and thus can’t be used by multiple people, legally (and you might be at risk of getting banned if they detect it)
However, passkeys can and are available to be shared via password managers. They’re not locked to the secure chip on the device where they live usually. iOS’ Passwords app has a share button and 1Password lets you share passkey-containing items.
In fact, the QR code login feature makes it even easier to do a one-time sign in to your account for a friend, if you don’t want them to be able to login to your account indefinitely.
0: Netflix doesn’t support passkeys because their main audience is people signing in via smart TVs and whatnot, which largely don’t support CTAP or Webauthn in general)
>In general you shouldn’
Me to said companies: I will do what I want.
Said companies to you: sounds like what you want is to get booted from our service.
Me: Invents more new ways of being problematic for the company spreading the ideas to millions of others decreasing their profitability to almost nothing.
Me to company: Damn, guess you shouldn't have been an asshole about it, kind of backfired on you.
The responsible product owners will already have bounced 18 months prior after tweaking the stats to falsify the customer satisfaction rate and grabbing their bonus on the way out.
Ok so when is Netflix going unprofitable?