| ▲ | otter-in-a-suit 3 hours ago | |
I take passkeys over the unbearable cargo cult that follows LLM companies, namely companies' newly found obsession to "sign in via email". Ideally optionally followed by a 2FA (naturally, via text, delivered straight to my Mac, even further diluting the questionable security of the whole exercise) and naturally, to be repeated every 2 days or so, since "stay logged in" is the biggest lie after "I've read and accepted the ToS". Your phone (which is probably what, 80% of relevant traffic these days?) likely has a perfectly fine password manager built in. This "sign in via email" trend must be every scammer and phishers biggest dream come true... | ||
| ▲ | PaulHoule 3 hours ago | parent [-] | |
Almost everything has supported email-based password reset since 90's for all the problems it entails. I am looking at a new project that uses magic links sent by texts. I have been there and done that with authentication systems and that's good enough for a low stakes ludic activity. | ||