3 ms·
I set my father (late 70s) up with a physical passkey (yubikey), and a backup key. He uses it for the important accounts (google, apple, bank, etc). It’s been
by lokar 16d ago
I set my father (late 70s) up with a physical passkey (yubikey), and a backup key. He uses it for the important accounts (google, apple, bank, etc).
It’s been fine.
- ChoGGi 16d agoYep, I've never had Google, PayPal, or Amazon ask me about a passkey with a yubikey.
- lokar 16d agoThe current ones are passkeys
- bootlooped 16d agoThis is why I've always been a fan of these. They are easy for laypeople to understand.
- jesseendahl 16d agoYubikeys generally have much worse recovery scenarios than passkeys do, for consumers. In enterprise if you lose your yubikey, an IT admin can help you get back into your account. If you lose a security key as a consumer, you're generally in a much tougher account recovery situation.
- lokar 16d agoYou need extra backup keys in a safe place. They don’t explain that well.
- 0cf8612b2e1e 16d agoNot all services let you enroll multiple keys. Amazon, with all the money in the world, was guilty of this for a long time. Practically, it is a huge challenge. I would want my day to day fob, an onsite backup, and an offsite backup. That’s a lot of hassle and potential for mistakes. To even register the offsite backup means I need access to it. Remotely copying a password database is so much reliable
- atanasi 16d agoIf you use a security key only for the most important accounts like Apple or Google, keys are set up once and then unchanged for years.