• AggressivelyPassive@feddit.de
    link
    fedilink
    arrow-up
    1
    ·
    1 year ago

    Maybe I’m misinterpreting something here, but wouldn’t that mean, I can’t just access my account if I lose my auth device? Am I supposed to always have a passkey device locked somewhere safe?

      • AggressivelyPassive@feddit.de
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        So, it’s just a password with a different name.

        Seriously, what is the functional difference between this and stricter password requirements? I don’t see it.

        • robobrain@programming.dev
          link
          fedilink
          arrow-up
          1
          ·
          1 year ago

          Passkeys use a challenge/response protocol that doesn’t transmit any actual secrets. This makes them phishing resistant as you can’t just “type in your passkey secret” it gitnub .com