logoalt Hacker News

pona-ayesterday at 7:00 PM1 replyview on HN

A passkey is always one per site. Emails tend to be naturally reused, unless the visitor uses a paid aliasing service (plus trick is trivial to canonize, having a dozen mailboxes on a self-hosted email still associates them with each other, because there's no anonymity set to speak of, and major email providers like Gmail won't let you register an account today without a phone number, credit card, or passport).


Replies

zwnowyesterday at 10:37 PM

And yet your passkey and therefore app access is tied to a singular key connecting that with all the user info.