<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Random Thoughts on Timbits</title><link>https://blog.timcappalli.me/categories/random-thoughts/</link><description>Recent content in Random Thoughts on Timbits</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>timcappalli@cloudauth.dev (Tim Cappalli)</managingEditor><webMaster>timcappalli@cloudauth.dev (Tim Cappalli)</webMaster><copyright>© 2026 Tim Cappalli</copyright><lastBuildDate>Fri, 27 Feb 2026 15:22:57 +0000</lastBuildDate><atom:link href="https://blog.timcappalli.me/categories/random-thoughts/index.xml" rel="self" type="application/rss+xml"/><item><title>Please, please, please stop using passkeys for encrypting user data</title><link>https://blog.timcappalli.me/p/passkeys-prf-warning/</link><pubDate>Fri, 27 Feb 2026 15:22:57 +0000</pubDate><author>timcappalli@cloudauth.dev (Tim Cappalli)</author><guid>https://blog.timcappalli.me/p/passkeys-prf-warning/</guid><description>Passkeys are the future of authentication, but using them for data encryption is a disaster waiting to happen. Overloading these credentials creates a dangerous blast radius that can lead to the irreversible loss of a user&amp;rsquo;s most sacred memories and documents.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://blog.timcappalli.me/p/passkeys-prf-warning/featured.jpg"/></item></channel></rss>