3 ms·
It is preventing password reuse and ensuring key complexity. The implementation of the credentials manager on the device storing the passkey should also ensure
by Wool2662 3y ago
It is preventing password reuse and ensuring key complexity.
The implementation of the credentials manager on the device storing the passkey should also ensure 2factor auth for use of the key.
Further passkeys are highly phishing resistant since they are bound to one specific domain and the passkey manager enforces that it is only transmitted to said domain.
It is basically a phishing , credentials stuffing, brute force resistant password that should ensure 2factor authentication.
It is pretty much the spot between dedicated hardware keys and still usable for the normal guy.
The only thing I dislike is that every provider can lock you in their "passkey ecosystem" since they only sync between them etc.