| ▲ | TacticalCoder 3 hours ago | |
> Passkeys do marginally improve security against MITM and phishing attacks ... The tragedy of passkeys is that they're a step back from the security offered by the likes of Yubikeys. But because passkeys are pushed by both Google, Microsoft and Apple: there is is simply no fighting these three. It is impossible. Passkeys won not because they're better (they're not and the entire concept of "secret behind a hardware security module" that can be transferred to another system defeats the whole point of a HSM in the first place) but because the powers-that-be decided that passkeys are to be used. It's still a win: the commoners are better served with passkeys. But a secret in control of Google/Apple/Microsoft that can be backed up is not a secret I control: it's a complete step back from yubikeys. Passkeys won and we better get used to them (and, yup, there are usability issues as you mentioned). | ||