logoalt Hacker News

whartungyesterday at 6:00 PM3 repliesview on HN

So how well do passkeys work when you don't sync passwords. When you bounce from machine to machine. From OS to OS.

How well does password recovery work in those scenarios?


Replies

AnotherGoodNameyesterday at 6:11 PM

This is a really common question but it has a really simple answer. They still have recovery methods. You can optionally change these with most providers (go into account settings, setup something like a recovery codes and check the option to be completely passwordless) but regardless they still have recovery methods. As in i lost my phone and i recovered the account with a combination of my secondary email and old password.

You might argue "but if they still have the recovery methods isn't my account only as secure as those" and to that i'd point out that you're still way ahead with passkeys simply by not entering passwords on a routine basis. The recovery methods tend to be two factor as well, just without passkeys as one of the two factors (hence email+password) so still a win over password alone in any case.

Passkeys should be thought of as no different to the old two factor authenticators. I mean that's literally what they are, essentially the latest fido standard that allows devices such as your phone to be a hardware security key in its own right. These always had ways to do account recovery with all the providers.

nixpulvisyesterday at 6:42 PM

Should allow multiple passkeys. So you have one per device.

show 1 reply
hanikesnyesterday at 6:08 PM

It works great with physical keys. Just need one as backup you leave at home.

show 1 reply