| ▲ | HackerThemAll a day ago | |
Rather: passkeys are great, but the way Microsoft implemented them in their login flow it disastrous. I store passkeys in a device-independent way, in KeePass using the great actively developed KeePassPasskey extension, because my threat model allows storing password and 2FA for the same site in the same place (or 1st factor when an account is passkey-only, i.e. passwordless). And I sync that between my primary computer and the phone. I have backups of my KeePass database in a few places (that don't require a passkey to log in) so I am able to regain access to core services in case both my devices fail at the same time. Although it's easy to trap yourself in a circular dependency. | ||