Hacker News new | ask | show | jobs
by cuu508 1485 days ago
WebAuthn is more convenient but also more secure. You don't have to be as vigilant when checking what URL your browser is pointing at.
1 comments

Not the GP, but I also use YK as a primary auth mechanism and TOTO as fallback.

Since I only use TOTP as fallback, I am much more vigilant if I suddenly get a TOTP prompt. I should never get one, only in circumstances where I explicitly want one. Every other instance is a big red flag. Is that perfect? No. Is it better than TOTP: yes.