• Glitchvid@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    Really depends on what you mean by passkey, since it’s actually a fairly vague term for a bundle of technologies.

    I don’t really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.

    But I’m a big fan of hardware 2fa using non-resident keys (“passkey” lite); I’ll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      Even pw synced passkeys at least have the benefits of both being phishing resisting + replay protected, as well as being able to use the TPM chip for extra local protection.

      Hardware keys are logically simpler though