4 ms·
Pass keys are a solution that will probably win, because it's very attractive to the device developers. They're portable, from one device to another, but only u
by GauntletWizard 2y ago
Pass keys are a solution that will probably win, because it's very attractive to the device developers. They're portable, from one device to another, but only using the developer's private apis.
U2F is better cryptography - the device key never leaves, but this is precisely what makes it hard for users. Losing a U2F key is risky, yet you have to carry it around with you. You can do what I do - Have a second U2F device registered everywhere, so that if the travel one is lost,
But I just experienced the second pain- I had a phone die on me. This seriously messed up my life for a week - every provider that used phone verification or text verification was inaccessible.
As developers, I beg you not to go to exclusive Passkey support. Keep UN/PW/U2F support around, and support multiple second factors.
Really, the problem is as simple as this: there's way too many bad actors, they have knowledge of tech, and little risk.