logoalt Hacker News

stavrosyesterday at 11:45 PM3 repliesview on HN

No, the biggest issue with passwords is phishing. You can't phish a passkey.


Replies

NoGravitastoday at 3:06 PM

Sort of. Passkeys push the phishing to the account recovery or passkey enrollment process.

show 1 reply
bgbntty2today at 8:24 AM

The problem with this is requiring everyone to own a device with a secure enclave or similar hardware capabilities because some people are prone to being phished. Let me choose the level of risk I find acceptable.

show 1 reply
AlotOfReadingtoday at 12:03 AM

Are there any credential managers that don't validate the domain with passwords? Sure, there are issues with PSL subdomain matching, but at the end of the day it's good enough in the real world. All the other stuff (MITM, malicious site, etc) falls under the other case I already mentioned.

show 1 reply