3 ms·
I think eventually, a lot of auth on the web will move to WebAuthn (when SSO isn't used). However, one could potentially allow users to add 1-N credentials. F
by sandstrom 4y ago
I think eventually, a lot of auth on the web will move to WebAuthn (when SSO isn't used).
However, one could potentially allow users to add 1-N credentials.
For example, a PassKey (WebAuthn) synced across devices, and then a WebAuthn credential stored on a Yubikey.
That way, you'd still need two factors, and hacking the computer alone isn't enough. But there is no "traditional" password involved.