(no title)
konha | 1 year ago
Passkeys can:
- Replace the whole login (including discovery of the user id)
- Just replace the password, after a user specified a user id
- Be used as a second factor just like TOTP
They are definitely more phishing resistant for what it’s worth, even if just used for MFA. TOTP codes can be copied manually by an unsuspecting user.
Raed667|1 year ago
stpn|1 year ago
[0]: https://web.dev/articles/passkey-form-autofill#fetch_a_chall...
mderazon|1 year ago
ecesena|1 year ago
If you want to explore more options.