Hacker News new | ask | show | jobs
by cadamsdotcom 8 days ago
Ok so we are achieving interoperability by turning passkeys into strings.

You know what it's called when you store a secret string in your password manager?

A password.

3 comments

> You know what it's called when you store a secret string in your password manager?

You keep changing your comment, but on the off chance you're still throwing shade.. Filippo probably wrote your password manager (or the code it runs, or the code your docker/kube system runs), and the decoder on the other end.

The user still needs to provide proof that they own the passkey in order to login. It's not like someone could hack the website, steal the "string" and use it to login.
That's his point - he's demonstrating a proposed standard that would make storing passkeys server-side almost as easy as passwords.