3 ms·
Yes but the same logic about loosing the secret applies to passwords and any other factors (given we ignore a potential reset process) Providers will most of t
by ffo 2y ago
Yes but the same logic about loosing the secret applies to passwords and any other factors (given we ignore a potential reset process)
Providers will most of the time allow to register multiple passkeys or other authentication means, hopefully ;-) which has its own downsides.
I am well aware how the internals work of keystores. But the benefit with "client certs" is that on mTLS you get added benefits besides where the key is stored. And that is that you can "prevent" mitm attacks.
But I guess that is a subject for another thread.
- formerly_proven 2y agoResident passkeys really are just the 2020-JavaScript version of X.509-based mutual authentication - naturally it's incompatible with anything but the web, sits on a weird level of the stack, and is somehow even less transparent to the user. On the other hand, certificate slots still seem to run approximately a dollar each.
- ffo 2y agoHaha comparison made me giggle.