| ▲ | MeetingsBrowser 2 hours ago | |
> By using passkeys, you gain better security against man-in-the-middle attacks but face the higher probability scenario of losing access to your accounts. > Phishing through the standard login flow is eliminated by passkeys, but it creates a false sense of security. An account’s security is still dictated by the weakest recovery method: SMS, email links, security questions, and so on. Passkeys are too strong and may cause account loss. Passkeys are too weak and can be bypassed by account recovery. | ||
| ▲ | beej71 an hour ago | parent [-] | |
> Passkeys are too strong and may cause account loss. Passkeys are too weak and can be bypassed by account recovery. Turns out, given the variety in the ecosystem, both these things are true depending on where you look. | ||