logoalt Hacker News

SoftTalkertoday at 1:19 AM1 replyview on HN

It seems like I have to trust more things that aren't very intuitive and are out of my control for passkeys to really be secure. For passwords, I only need to trust myself. I trust that I don't lose them, don't re-use them, and don't fall for phishing attacks.

Of course I also have to trust that whatever service I'm authenticating to does their part correctly, but that's the same either way.

I'm going to continue to use passwords.


Replies

loegtoday at 1:24 AM

This is an insane and uninformed take. The malware described in TFA can even more trivially harvest passwords, which have never lived in a TPM. Passwords offer no security benefit over passkeys.