Hacker News new | ask | show | jobs
by passkeyspoor 976 days ago
The point is that the phone with a crappy 4 digit pin can be used to authenticate everything on every device the user owns that uses passkeys. It's a one stop shop of failure.
1 comments

Phones are already that way. They have text messages and email which is enough to log into almost any service.
The argument is that without your phone, you likely have no recourse to stop the attack. Since your passkey on the phone is what controls your access, now.
Yes, that's also bad. They're both bad. Passkeys are worse.