4 ms·
Passkeys are the 2026 answer. No (added) username, no password, no two factor SMS, no phishing.
by dweekly 7mo ago
Passkeys are the 2026 answer. No (added) username, no password, no two factor SMS, no phishing.
- jwr 7mo agoUntil you lose your device or it breaks suddenly.
- mikepurvis 7mo agoI store passkeys and totps in 1Password. I know it means there's no hardware protection of the secure element, but in return they're trivially synced across my devices. I feel this tradeoff is worth it to me; certainly it is no worse than email or SMS as the second factor.
- dweekly 7mo agoChrome Sync, iCloud Sync. There are great answers for this.
- jwr 7mo agoSure. But if you sync passkeys, are there any advantages apart from phishing protection? The biggest advantage for me is using the hardware secure enclave, thus effectively getting a 2nd factor.
- teej 7mo agoPasskeys are auth garbage. Normal users do not benefit from overly complex auth.
- dweekly 7mo agoYou tap your finger and you're done. Faster than a password paste. How is that complex or difficult UX?
- mikkupikku 7mo agoToo confusing for me, I don't get it. How do I record my login info on paper so my family can get in if I die?
- xienze 7mo agoI'm not a fan. But what Anthropic SHOULD have done is use plain ol' SSO. Google, GitHub, Microsoft, etc. logins with the option to do this magic link stuff. The third party auth providers would use passkeys at the user's discretion.
- lostmsu 7mo agoDon't they have Google SSO?