Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I don’t think that github has to know that. You could be using a password manager and choose to make it a minimum character boring password or meet minimum complexity requirements or use the same password on a million sites. You have to secure your credentials; complying with the minimums of a service isn’t security.
GitHub doesn’t need to know that - I think that’s why it’s a bit of a cop out for MFA. Sure, your bitwarden may implement MFA, but just a chrome browser isn’t MFA.
Passkeys enable sites to offload the responsibility of securing accounts to the user, and if the user chooses a weaker way to implement them, GitHub doesn’t give a fuck.
Unless your bitwarden has MFA and locks after an amount of time commensurate with your security needs
True, but how does GitHub know your bitwarden has MFA? It only knows something has a valid credential.
I don’t think that github has to know that. You could be using a password manager and choose to make it a minimum character boring password or meet minimum complexity requirements or use the same password on a million sites. You have to secure your credentials; complying with the minimums of a service isn’t security.
GitHub doesn’t need to know that - I think that’s why it’s a bit of a cop out for MFA. Sure, your bitwarden may implement MFA, but just a chrome browser isn’t MFA.
Passkeys enable sites to offload the responsibility of securing accounts to the user, and if the user chooses a weaker way to implement them, GitHub doesn’t give a fuck.
Github doesn’t need to know how you implement it, just that your browser is handling it (and in this case the browser lets Bitwarden handle it lol)