• ExtremeDullard@lemmy.sdf.org
    link
    fedilink
    arrow-up
    11
    ·
    edit-2
    26 days ago

    I’m all for MFA, but ultimately, a GOOD password - or rather, a good password recipe - that resides in my brain must be included in the mix as far as I’m concerned. Because unlike other forms of authentication, that one can never be extracted, stolen or recovered without torturing me.

    So you can have your passwordless future: I’ll keep my passwords - in combination with other forms of authentication of course. Passwordless is lesser security for the lazy.

      • EngineerGaming@feddit.nl
        link
        fedilink
        arrow-up
        2
        ·
        24 days ago

        The whole idea of the site not having a “secret” to leak is awesome. I find passkeys interesting as long as they stay in my control and are easily backupable (like in KeepassXC). However, I am not sure whether the passkeys coming from different sources are distinguishable, which might lead to sites restricting you to Big Tech ones.