Hacker News new | ask | show | jobs
by c7b 24 days ago
That's highly misleading to outright misinformation.

> Passkeys don't have to be remembered

Because you need an app for the login flow. You also don't have to remember passwords if you use a password manager app.

> don't need 2FA

Not true, a second factor in the form of eg a biometric ID or PIN is mandatory.

Phishing resistance exists, but only truly so if you completely surrender control over your device and access to your credentials. Something that the same organizations who you'll depend on for Passkeys are actively pushing for through various initiatives.

1 comments

No it is not. You’re free to save passkeys in your manager of choice and it still won’t let you use a passkey on the wrong website. Users are freed from having to copy&paste TOTPs. No app other than a browser needed.