logoalt Hacker News

winstonwinstonyesterday at 11:59 PM1 replyview on HN

Using strong password as you suggested is a solved problem for your use case, but that is not universal. Passkeys provide universal security for all.

Also PIN or biometrics verification to access passkey from device bound TPM or security enclave solved the problem you implied might happen, such as losing your device. How do you protect your password manager, if any?

> even those can have vulnerabilities.

We shouldn’t just give up because everything is inherently insecure.


Replies

rarontoday at 5:29 AM

> We shouldn’t just give up because everything is inherently insecure.

True, but no sane way to mass revoke Passkeys from stolen / lost device is just bad design.