Hacker News new | ask | show | jobs
by JoBrad 785 days ago
The services that I use passkeys for (MS, AWS) do. I have separate passkeys for 2 browsers and on my phone.
1 comments

The trouble is if it is on the service to do the support, they can revoke support at any time. They could use start tightening the screws on device attestation tomorrow for business reasons and drop support for your browser or phone.
How would we add MFA (in the broadest sense) without services supporting it? Or multiple MFA devices?