3 ms·
Ultimately, passkeys are just certificate based authentication. Certificates are generally more secure because they contain more entropy (and because they conta
by pat2man 4y ago
Ultimately, passkeys are just certificate based authentication. Certificates are generally more secure because they contain more entropy (and because they contain metadata). But nothing is stopping you from using something like a mnemonic phrase that you remember to generate a certificate. It would be trivial to create a browser extension that allowed you to use a "password" on a passkey enabled site. If thats the experience you want I am sure someone will provide it.
- vouaobrasil 4y agoYour proposed solution isn't a very good one. Actual password systems use server-side things like salts and other mechanisms like hashing. Having "trivial" client-side extension to generate a certificate would make brute-force a lot easier. So, if passkeys are the only way of logging in, then no, a browser-based certificate generator would not work to emulate passwords.