3 ms·
> aren't we largely back to passwords? A password is a shared secret. Even if it's hashed on the server side, one could brute force it if a weak algorithm is u
by tehbeard 3y ago
> aren't we largely back to passwords?
A password is a shared secret. Even if it's hashed on the server side, one could brute force it if a weak algorithm is used, or MiTM the service to get the plaintext when the user logs in.
Passkeys / webauthn utilizes public key cryptography. I'm only ever giving them a (by the spec, unique to the combo of me and the site in question) public key to which I hold the private key pair.
Authentication doesn't involve transmission of these, it's challenge based where you prove you have access to the corresponding private key.