logoalt Hacker News

Slackwisetoday at 8:14 PM1 replyview on HN

I recently logged into my CVS.com account after not touching it for years, and I couldn't find the password reset..... turns out they no longer use passwords at all; only Passkeys and tokens via email/SMS.

Aside from email accounts potentially being compromised or SMS interception, this is honestly the way all sites should be going now. But more seriously, there should be a way to use only Passkeys with a backup identification method in case you lose your Passkey.

The new threat? Browser password managers are insecure. Anyone can sit down at my machine if it's unlocked and Passkey their way into any of my accounts. What good is that? Why doesn't Chrome use my Google account password before allowing auto-fill/login? (Obviously I don't use Chrome's password manager, but it's a real concern for everyone else.)


Replies

epistasistoday at 8:21 PM

I agree with your anti-password take, 100%. But all my passkeys have biometrics attached to them, mostly so that I know that they are being used, when they are being used. Silent release of authentication credentials is a scary security mode. A YubiKey with a press mechanism is enough, I just happened to buy the biometric version. Or use the biometric lock on iCloud Keychain passkeys.