Hacker News new | past | comments | ask | show | jobs | submit login

"Dang, this stupid password manager seems to rarely autofill right, lemme quickly paste that in there...got it!"

You can never make this mistake with a passkey or FIDO authenticator.






You can still provide your Passkey password though to some scam. A centralized storage of your passwords.

There is no passkey password. If there are, it is entered into the dialog box not a site. And wouldn't do any good cause the passkey is saved on the device and does a key exchange.

If you mean the password manager password, then it is entered in a different place and really hard to confuse it with a website. Also, 1Password requires extra info to login account and that is only used, usually copying from another device, when setting up device.


The PIN for the hardware passkey device in my locked drawer at home is 1234567.

Oh no, you have its PIN! Can you now log in to $service as me?

Not without that hardware module.

My password for $service is hunter42.

Now you can log in as me.

See the difference?


I am trying to come up with a counter argument but gave up. Since you are correct.

Is it fine if a waive my hands around and say "complexity"?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: