Hacker News new | ask | show | jobs
by sanitycheck 1108 days ago
If a "reset passkey by email" option exists, they don't seem much more secure than a unique complex password + (non-SMS) 2FA.

So for most people on HN (who also probably won't be successfully phished) they offer only new problems, yet if implemented and used widely they're probably a net positive.

It's a bit like the Covid rules. I am more than capable of avoiding other humans without new laws, but "normal" people seemed to need a lot of coercion.

Personally I'll give it a few years and see how passkeys pan out before I switch (if I get the choice).