| ▲ | jayknight 2 hours ago | |
What services implement it like this? Don't services usually implement passkeys as a more secure alternative to a password, but password login is still available? Some sites allow passkeys as an option for MFA, so that could be an issue if the passkey is your only MFA option and MFA is required. But I imagine email would pretty much always be a fallback. | ||
| ▲ | mrweasel an hour ago | parent | next [-] | |
Didn't Outlook.com famously rolled out passkeys with no recovery option and no option to sign in using username and password once enrolled. So if you lost your trusted device, you couldn't sign in, nor could Microsoft send you an email, because... Outlook.com is your email provider. I don't know if they fixed it, they probably did. Edit: Maybe not, because the recovery option at the end is just nuts: https://learn.microsoft.com/en-us/answers/questions/5454924/... | ||
| ▲ | basch an hour ago | parent | prev [-] | |
When was the last time you tried to log into something like Google, Apple, Microsoft etc without your phone nearby, on a fresh computer? | ||