| ▲ | unethical_ban 3 hours ago | |
Infosec for 15 years, and I do not want passkeys either. Anything that attaches itself to hardware is susceptible to loss. Anything that attaches itself to hardware makes it harder to use services from a new device. At some layer you have be able to access your services with password/totp if only for recovery. Passkeys add a layer for minimum benefit, in my opinion. Yes, push based totp and passkeys are more phish proof but for non techies, managing them is its own job. | ||