Hacker News new | ask | show | jobs
by CGamble26 1138 days ago
This may be a dumb question but, why couldn’t applications just use Webauthn? Why add passwords?
1 comments

The only reason probably if some accounts already have a password and you want to support it. If you're building a new app, I'd also go for WebAuthn / passkeys-only and use some other passwordless method (e.g. social login/OIDC or email magic links as fallbacks)
Ok understood, thank you very much!