3 ms·
It looks like a good change for the average user, a secret stored on the device is likely a whole lot safer than just having a password. Having it as the only f
by dtech 3y ago
It looks like a good change for the average user, a secret stored on the device is likely a whole lot safer than just having a password. Having it as the only factor seems less secure than password + good extra factor like TOTP on device though.
I also wonder how a lost/broken/replaced device is dealth with, especially given Google's less-than-stellar account lockout history.
edit: I guess this is still MFA since you need both the physical device and a fingerprint and phone unlock code
- barkerja 3y agoPasskeys can also be used in addition to passwords, as a form of 2FA. I've seen a number of sites approach Passkeys in this manner. Or if you really wanted to, you could flip it. You can allow the Passkey to be the "password" and an actual password the second-factor for the user.