Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

  • Engywook@lemmy.zip
    link
    fedilink
    English
    arrow-up
    37
    arrow-down
    1
    ·
    2 days ago

    No, thanks. I’ll keep using password+2FA and I hope that passkeys never become “mandatory”.

    • TotalCourage007@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      2 days ago

      Thanks to our dystopian hellscape we live in it’ll become mandatory just like useless online ids. I hate having to explain passkeys to my family. Some fuckface suit who doesn’t use it properly pushed for a portfolio addition.

      • sonofearth@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        1 day ago

        But what’s dystopian about passkeys? They are actually more secure than Password + TOTP. Phishing out a passkey is practically impossible.

        • TotalCourage007@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          If its not fully functional it feels more like a vendor lock in than anything actually useful. Use a Google device but want to change? Oh I’m sorry you have to do all this work first thanks to passkeys.

          Some websites are better about it but they can also have support in-fighting over which service works better. Its the Password Manager scenario all over again but worse.