logoalt Hacker News

vel0citytoday at 1:37 AM1 replyview on HN

> people use 2factor authentication and Passkeys without respecting the same truth.

Passkeys are still your keys. You can put them on hardware authenticators you control entirely offline separate of other services. You can store them in software vaults you manage.


Replies

throwawayk7htoday at 5:21 AM

that's not true. Passkeys have an optional remote attestation capability, which second parties can use to completely enforce aspects of your keys, such as them being non-transferrable or not usable without a screen touch etc.

show 2 replies