Hacker News new | ask | show | jobs
by labcomputer 668 days ago
Re replay: No, because once someone has your password they can replay it as many times as they want. If you use your passkey on a compromised computer, the intercepted credentials can’t be reused.

Re DB leak: No, you the concern is reused passwords (or similar passwords) from a different site.

Re phishing: Yes, but one of the FUDs against passkeys is that they lock you in to a vendor. There is no more lockin than if store your passwords in a manager.