Hacker News new | ask | show | jobs
by denton-scratch 1082 days ago
> so passkeys are a much better and easier method

Thing is, most people don't understand passkeys. If you want to be secure, then you want to understand why and how you're secure; a pinky-promise that you're secure doesn't cut the mustard.

I do have some understanding of this kind of technology, having written for myself an OAuth server back in the day. I gave up on the server, because the services I wanted it for (bank, tax, medical) didn't accept OAuth, and because it was much too hard to understand.

Passkeys involves more third parties, and is even harder to understand.