| ▲ | xp84 3 hours ago | |
The article asserts with little proof that lockout risk is a big problem. But consumer sites themselves basically 100% of the time have a recovery path that amounts to a SMS code or emailed code. The only part that is very persuasive is the part about storing your passkeys with Google or Apple integrations, and what happens if they ban your account. But the same argument would apply if you’re only storing your passwords in a Google or Apple password manager. I use passkeys and I always store them in a password manager I control - but usually I also store another one in the OS on Windows, Apple, and Google. Best of all worlds. Also, I appreciate that idiots aren’t forcing me to “change my passkeys” every 90 months like they STILL do with passwords! | ||
| ▲ | buckle8017 3 hours ago | parent [-] | |
Passkeys are mostly useless because of that. Their security is nearly universally undermined by reset mechanisms. There are virtually no sites where passkeys cannot be bypassed. | ||