3 ms·
Yes, thank you. Maybe I am getting old but password+yubikey/webauthn was really top UX.
by blfr 16d ago
Yes, thank you. Maybe I am getting old but password+yubikey/webauthn was really top UX.
- mschuster91 16d ago> Maybe I am getting old but password+yubikey/webauthn was really top UX. It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...
- xxs 16d agoWhat prevents passkey being used alongside password (+ email 2fa)?
- blfr 16d agoEmail 2fa otoh is the worst UX I have experienced. I curse every time Claude sends me a magic link. Absolutely hate them.
- esafak 16d agoYou don't like not having to worry that they don't store your creds so they can't lose it?
- blfr 16d agoThe creds they store hold no value. These creds only give access to their system anyway. They store the email address either way so the situation is no better but less convenient.
- xxs 13d agoNot sure this is what I meant. Password is still stored, along will all the keypass stuff. If you have the option to login with the keypass... or the password - possibly sending you a link (or code) to the email, in case the device/browser has not been seen, yet.