Hacker News new | past | comments | ask | show | jobs | submit login

I disagree that a proper key-based solution wouldn't have security benefits (auto-fill doesn't always work and is more vulnerable to phishing).

But I also really want to be clear here that we are not talking about multi-factor authentication in the long run. The explicit goal of Google/Microsoft/Apple is to get rid of passwords. Passkey is designed as a replacement for passwords. It's not a replacement right now, but that is the intention, they are not thinking about having a Yubikey as a second-factor for login.




When I said "auto-fill", I was referring to auto-fill with a browser extension where the website is checked. Yes, the FIDO method is even nicer from a technical perspective, but from a security perspective they are similar.

But of course, you can be phished into copying your password into a phishing site. So there are benefits, but it's not a huge difference in this one specific context (no physical token, using a password manager with a browser-extension-based auto-fill).




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: