| ▲ | ealready_value 3 hours ago | |||||||||||||
"Oh, usually my bank just logs me in, that's strange. Let me just go grab my username and password and type it into this site that looks like my bank." Same thing is going to happen with passkeys for non-technical users for exactly the same reason you stated. People will think the integration is busted and manually copy/paste the non-passkey credentials in. In that way, I would argue that passkey is not stronger protection against phishing attacks unless its the only way to login. It is, at best, a convenience for users. | ||||||||||||||
| ▲ | Latty 2 hours ago | parent | next [-] | |||||||||||||
If the user just has a username/password fallback and that's it, then yes, but the aim of passkeys is that won't be the norm, rather users will only have passkeys and the fallback would be to, e.g: magic link email log in where the phishing attack is still broken. I've seen some sites explicitly disallow plain username/password login after you enable passkeys for this reason (you can still put them in, but then it just does a magic link flow afterwards as a second factor). | ||||||||||||||
| ▲ | pamcake 2 hours ago | parent | prev [-] | |||||||||||||
The pitch is that passwords will supposedly be phased out entirely as an option. | ||||||||||||||
| ||||||||||||||