ljrk,
@ljrk@todon.eu avatar

@faebudo @GossiTheDog Fair. This is a whole different topic though and not about the security of Passkeys and I wholeheartedly agree with you there. I don't use either of their implementations but BitWarden (OSS, self-hostable).

Google were among the first to support HW Authenticators IIRC. But still, nobody really used them. There's a key issue: You need two enrolled everywhere, one as a backup in case of loss.

Now, however, every time you register somewhere you of course need to register both. So you can only register a new login at home when you have the backup close by anyway. This... is honestly quite unrealistic for almost everyone. Hardware tokens were designed for scenarios where few people had laptops or even smartphones, or the keys came managed from your employer.

They're not bad, but simply nothing I could make normal users use. I mean, I tried.

Now, if you really want to, you can still do that. Every site that allows login through Passkeys can be used with a hardware token too.

I do this for critical sites and my keychain (so my Passkeys are secured by a YubiKey).

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • modclub
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • cubers
  • GTA5RPClips
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • tacticalgear
  • ethstaker
  • kavyap
  • Durango
  • anitta
  • everett
  • Leos
  • provamag3
  • mdbf
  • ngwrru68w68
  • cisconetworking
  • tester
  • osvaldo12
  • megavids
  • khanakhh
  • normalnudes
  • JUstTest
  • lostlight
  • All magazines