If a user doesn’t have a second factor, what should their first and only factor be? The passkey people are trying to posit that a passkey is better than a password as the only factor.
Second factor should be gradually ushered in everywhere over a period of years, starting with banking, until it becomes second nature for users. This would effectively end concerns over strong or reused passwords, and would make phishing incredibly difficult.
Under this scenario, the first factor can be a short password or even a PIN.
Second factor should be gradually ushered in everywhere over a period of years, starting with banking, until it becomes second nature for users. This would effectively end concerns over strong or reused passwords, and would make phishing incredibly difficult.
Under this scenario, the first factor can be a short password or even a PIN.