Hacker News new | ask | show | jobs
by m-p-3 911 days ago
It depends if you use a hardware token or a password manager that supports Passkeys.

If it's the hardware token, then the "certificate" (which can either contain your username or not aka discoverable vs non-discoverable credentials) that private key required for authentication will be stored and cannot be extracted in the secure element (until an exploit is found).