Hacker News new | past | comments | ask | show | jobs | submit login

You're not locked in. Want to switch? Add a passkey. Lose all your passkeys? Do the "forgot password" thing just like you've done forever.



The "forgot password" flow involves accessing your email. And accessing your email without having access to your passkey requires a device that has previously logged in to your email. And the device that has previously logged in to your email is the same device where your passkeys are stored, which is to say, the same device that is now lost or bricked, which is the reason your passkeys are lost in the first place.

And sure, you and I have multiple devices. We're in the minority. Most people just have the one. Without another way in, they're irrevocably fucked.


You only use your passkey when logging in to your email account if you use a web-based client exclusivley.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: