top | item 44453296

(no title)

kd5bjo | 8 months ago

> There’s no difference with a password, except that the sign-in process can be streamlined when everything works

There is one other major difference behind the scenes: With passkeys, the service you’re logging into never has enough information to authenticate as you, so leaks of the server-side credential info are almost (hopefully completely) useless to an attacker.

discuss

order

jbverschoor|8 months ago

Sure, but that would mean the service is likely to be useless as well.

And, you’re likely to loose access to your service. It’s like would you rather loose your pictures forever, or have them copied by someone