Skip to content

Comment on Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Comments

It seems like I have to trust more things that aren't very intuitive and are out of my control for passkeys to really be secure. For passwords, I only need to trust myself. I trust that I don't lose them, don't re-use them, and don't fall for phishing attacks.

Of course I also have to trust that whatever service I'm authenticating to does their part correctly, but that's the same either way.

I'm going to continue to use passwords.

This is an insane and uninformed take. The malware described in TFA can even more trivially harvest passwords, which have never lived in a TPM. Passwords offer no security benefit over passkeys.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.