logoalt Hacker News

stavrostoday at 12:07 AM2 repliesview on HN

There's a big difference between "generally doesn't get phished" and "it's impossible to be phished".


Replies

AlotOfReadingtoday at 12:22 AM

It's security, so we're not discussing impossibility. You can still phish a passkey, we're just hoping the cryptography is good enough that it remains astronomically unlikely to succeed. Since we're all reasonable people, that chance is low enough that we're fine accepting it. What I'm saying is that the chance with passwords is still low enough that I'm fine accepting, even though it's much higher than the cryptographic security of passkeys. We're simply disagreeing about where we draw the line of "good enough".

show 1 reply
immibistoday at 11:31 AM

What happens if i drop my phone in a river? Am I unpersoned, or is there a way to recover all my accounts? Just phish that flow instead.