|
|
|
|
|
by syllablehq
1044 days ago
|
|
Interesting, I hadn't followed this in a while, and it does sound like this is getting closer to an open standard... But it sounds like the discussion of it gets mixed up with other muck including biometric, 2-factor, proprietary tools, TOTP auth etc. Seems we need a first step that ONLY focuses on abstracting the password away and still letting email be a natural reset. Seems to me that the standard should simply allow someone to delegate their "passkey keeper" of choice to be the authentication engine that tracks tokens. It can be up to the user (up to their passkey tool) to decide everything else. But set up a system that let's us log in without a password, and without a proprietary auth system like google or facebook etc. https://arstechnica.com/information-technology/2022/05/how-a... |
|
I'd literally get dozens of emails a day. Absolutely not. Passkeys are the solution. Literally everyone whining and complaining and imagining up ideas in this thread ... It's webauthn and passkeys and can we stop wasting our keystrokes over it.