Remix.run Logo
morgoo a day ago

One of the big benefits of passkeys is that you can completely remove the ability to log in with a password!

tcoff91 a day ago | parent | next [-]

Just spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery.

So no password login, but then you can recover your account by adding an additional passkey by receiving an email.

jayknight a day ago | parent [-]

Just make sure you don't lose the passkey to log into your email.

Synthetic7346 a day ago | parent | next [-]

Isn't it the same as my password manager's vault? I only remember my master password so if that vault is lost I can't even log in to my email

jayknight a day ago | parent [-]

Kind of, but I have some of my most important passwords and account recovery codes duplicated on paper in a secure place. If there was ever a service that only allowed passkey login (do those exist?), you can't print those out.

tcoff91 a day ago | parent | prev [-]

I'd still prefer password+2fa+backup codes for email.

nunez a day ago | parent | prev [-]

I wouldn't be okay with that. Say you're setting up a new iPhone with a new iCloud account because you forgot the password to your old one. (Unlikely scenario amongst us nerds, but very very likely outside of our bubble.)

If you want to log into, say, Google, but the passkey flow is the only way in, then you're almost-completely SOL unless you have some way of getting the passkey out of your iCloud keychain and into the keychain of the phone you're setting up.

If you still have your old phone, you can scan the QR code and get in that way. If you don't, then you're completely SOL.