Remix.run Logo
tcoff91 a day ago

Just spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery.

So no password login, but then you can recover your account by adding an additional passkey by receiving an email.

jayknight a day ago | parent [-]

Just make sure you don't lose the passkey to log into your email.

Synthetic7346 a day ago | parent | next [-]

Isn't it the same as my password manager's vault? I only remember my master password so if that vault is lost I can't even log in to my email

jayknight a day ago | parent [-]

Kind of, but I have some of my most important passwords and account recovery codes duplicated on paper in a secure place. If there was ever a service that only allowed passkey login (do those exist?), you can't print those out.

tcoff91 a day ago | parent | prev [-]

I'd still prefer password+2fa+backup codes for email.