|
|
|
|
|
by epistasis
10 days ago
|
|
I agree with your anti-password take, 100%. But all my passkeys have biometrics attached to them, mostly so that I know that they are being used, when they are being used. Silent release of authentication credentials is a scary security mode. A YubiKey with a press mechanism is enough, I just happened to buy the biometric version. Or use the biometric lock on iCloud Keychain passkeys. |
|
So, therefore: passwords shouldn't exist, and you should create sessions via email links/tokens. Then also offer Passkeys as a faster login.