logoalt Hacker News

paulddraper • today at 1:37 PM • 1 reply • view on HN

Passkeys.


Replies

jackjeff • today at 1:49 PM

Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.

I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.

And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.

➕ show 1 reply