←back to thread

225 points Terretta | 1 comments | | HN request time: 0s | source
Show context
solarkraft ◴[] No.41860069[source]
I had hope for passkeys, with all the interop-promises.

It turned out that no (mainstream) passkey provider allows backups however, making them infinitely worse than just using passwords.

Maybe this will help, but fuck me, it’s all complicated, especially for a damn foundational security mechanism!

It could be so simple, just look at SSH keys, which I think largely use the same principle.

replies(5): >>41860481 #>>41863668 #>>41864115 #>>41864718 #>>41866900 #
1. arccy ◴[] No.41864718[source]
if you can get a backup, someone can get scammed into providing that to an attacker, taking away any security benefit.