|
|
|
|
|
by sanitycheck
1108 days ago
|
|
If a "reset passkey by email" option exists, they don't seem much more secure than a unique complex password + (non-SMS) 2FA. So for most people on HN (who also probably won't be successfully phished) they offer only new problems, yet if implemented and used widely they're probably a net positive. It's a bit like the Covid rules. I am more than capable of avoiding other humans without new laws, but "normal" people seemed to need a lot of coercion. Personally I'll give it a few years and see how passkeys pan out before I switch (if I get the choice). |
|