Hacker News new | ask | show | jobs
by epistasis 10 days ago
I agree with your anti-password take, 100%. But all my passkeys have biometrics attached to them, mostly so that I know that they are being used, when they are being used. Silent release of authentication credentials is a scary security mode. A YubiKey with a press mechanism is enough, I just happened to buy the biometric version. Or use the biometric lock on iCloud Keychain passkeys.
1 comments

I was trying to say, nobody should be using Passkeys via browsers because they all fail to secure them. You need a password manager of some sort. But this is also true of passwords. My ultimate point was, passwords are a burden because unless you use a password manager and unique passwords for every single account, then passwords are strictly a burden. The average user doesn't use a password manager outside of the junk in Chrome, so... they're really just creating a security disaster for themselves.

So, therefore: passwords shouldn't exist, and you should create sessions via email links/tokens. Then also offer Passkeys as a faster login.