4 ms·
It's also not a one or the other kind of thing. The ideal auth system makes use of both, with the passkey or hardware token as the MFA component and a strong p
by VoodooJuJu 2y ago
It's also not a one or the other kind of thing.
The ideal auth system makes use of both, with the passkey or hardware token as the MFA component and a strong passphrase as the traditional password component. In this way, you are protected from phishing, which is the final weak point that MFA methods like TOTP do not address.
Unfortunately, globocorps are pushing for passkeys as the sole means of authentication, rather than just the MFA component. Being cynical, I'm guessing they're doing this to facilitate some kind of vendor lock-in or fingerprinting.