this post was submitted on 26 Sep 2026
390 points (94.9% liked)

Technology

88272 readers
3099 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Kangae_Hishiryo@scribe.disroot.org 6 points 1 day ago (3 children)

The main problem is if that you lose the device that's physically attached to the passkey... You'll lose your account.

I'd just prefer a biometrics-first approach.

Unless hackers started cutting people's fingers, which is something just too risky for a rational hacker to do so it's more than improbable, biometrics are way more secure, consistent, battle-tested and most important, more convenient and, by design, unforgettable.

[–] PattyMcB@lemmy.world 12 points 1 day ago (1 children)

Naww... biometrics are easy to steal or coerce from people.

[–] warm@kbin.earth 12 points 1 day ago (1 children)

That's why you shouldn't use exclusive on device storage for them, like Apple/Google want you to. Biometrics are shit, I prefer passwords if we are having no passkeys. I agree they are not perfect, but we can improve them and they will be a lot better than passwords for the majority of people.

Also, you wont lose your account, youll just have to go through a recovery process. Exactly the same as you would now if you forgot a password or lost a MFA code.

[–] Natanael@infosec.pub 5 points 1 day ago* (last edited 1 day ago)

Biometrics is inherently not securable and the only viable method of using it ever is locally only to unlock a different secret, which actually can be secure.

Most biometrics is trivial to duplicate, fingerprints can replicated from photographs.

Biometrics are battle tested and got annihilated in every conflict. It's a total loser.