3 ms·
I've recently been looking into passkeys and it seems much simpler than this.
by cod1r 3y ago
I've recently been looking into passkeys and it seems much simpler than this.
- Manouchehri 3y agoPersonally, I would be worried about losing access to an account if I only relied on a passkey.
- jeroenhd 3y agoI don't really understand this problem. Just click the "forgot password" link (perhaps "lost passkey" for passkey-first services?).
- tesdinger 3y agoHow can I backup a passkey on a sheet of paper?
- jeroenhd 3y agoPasskeys and OIDC are not directly related. If all you want is "authenticate to AWS" then yes, passkeys would work, but so would a simple password, or a TLS client certificate, or whatever other technology you like for authentication. OIDC works for things like "use my employer's login to get access to AWS resources without having a separate AWS password". For certain OIDC authentication implementations, you can actually use passkeys. Standard passkeys should work perfectly fine with Keycloak's WebAuthn implementation, for example, either as a second factor or as the first factor in the login flow.