|
|
|
|
|
by mooreds
1083 days ago
|
|
Have you used webauthn with a platform authenticator? When properly implemented, it's as simple as FaceId or using your fingerprint to unlock your phone. Which are both things that normal folks have mastered quite well. The bigger issue is that you are currently locked to a device (or, in some cases to a set of devices). This makes it tedious, because: * you have to have an account recovery mechanism beyond the scope of WebAuthn * you have to add each device you want to login with We'll see if these issues get resolved, but I think that the working group is, well, working on it. |
|
What if my phone dies with all my keys?
Do I need to maintain backups on 3 devices? I assume manually to be secure. This is so much time, esp for throwaway nonsense accounts I use yearly.
What if my phone died during a trip and backups are at home in another country. How do I email someone now?
My mom forgets a password each time she has to retype it. What if she breaks her phone with all the keys and no backups.
How do I log in on a computer without usb access that is not connected to the same network as my phone with the keys? - this workflow is already broken with gmail 2FA process with approving in gmail/youtube app.
If I even reset a passkey, how to use a friends device if mine is broken currently?
This is all solved with a password reset email.