3 ms·
> Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their tr
by madog 15d ago
> Yes, there's the minimal risk of lockout if you lose access to the passkey (though almost every site I've used that implements pk's lays it on top of their traditional user/pass auth flow)
Exactly, if you lose your passkey you just sign in with your password like you did previously. I'm yet to find an app/website that has passkeys only and no passwords.
Seems like a total non-issue to me.
- morgoo 15d agoOne of the big benefits of passkeys is that you can completely remove the ability to log in with a password!
- tcoff91 15d agoJust spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery. So no password login, but then you can recover your account by adding an additional passkey by receiving an email.
- jayknight 15d agoJust make sure you don't lose the passkey to log into your email.
- Synthetic7346 15d agoIsn't it the same as my password manager's vault? I only remember my master password so if that vault is lost I can't even log in to my email
- jayknight 15d agoKind of, but I have some of my most important passwords and account recovery codes duplicated on paper in a secure place. If there was ever a service that only allowed passkey login (do those exist?), you can't print those out.
- tcoff91 15d agoI'd still prefer password+2fa+backup codes for email.
- nunez 15d agoI wouldn't be okay with that. Say you're setting up a new iPhone with a new iCloud account because you forgot the password to your old one. (Unlikely scenario amongst us nerds, but very very likely outside of our bubble.) If you want to log into, say, Google, but the passkey flow is the only way in, then you're almost-completely SOL unless you have some way of getting the passkey out of your iCloud keychain and into the keychain of the phone you're setting up. If you still have your old phone, you can scan the QR code and get in that way. If you don't, then you're completely SOL.
- epihelix 15d agoOk, so the big security risk that passkeys are supposedly designed to stop, is actually still there? If you can still be phished, remind me what the point of any of this was, again?
- madog 15d agoIgnoring any supposed security benefits, personally I use it because it's much more convenient/ faster than logging in with a password since. You're still slightly less likely to get phished if you only ever login with passkey and only use the password in case of lost passkey. Of course you could get phished that one time but entering your password once (maybe never) has got to be better than entering it daily. I don't have any passkey accounts where I didn't start off with a password and after adding a passkey the password login method was always retained. What services are people using where you don't need to set a password?
- deleted 15d ago[deleted]