logoalt Hacker News

cadamsdotcomtoday at 2:01 AM3 repliesview on HN

Ok so we are achieving interoperability by turning passkeys into strings.

You know what it's called when you store a secret string in your password manager?

A password.


Replies

gnabgibtoday at 2:04 AM

> You know what it's called when you store a secret string in your password manager?

You keep changing your comment, but on the off chance you're still throwing shade.. Filippo probably wrote your password manager (or the code it runs, or the code your docker/kube system runs), and the decoder on the other end.

fastest963today at 3:44 AM

The user still needs to provide proof that they own the passkey in order to login. It's not like someone could hack the website, steal the "string" and use it to login.

miloignistoday at 2:13 AM

That's his point - he's demonstrating a proposed standard that would make storing passkeys server-side almost as easy as passwords.