this post was submitted on 26 Sep 2026
390 points (94.9% liked)

Technology

88272 readers
3099 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] Glitchvid@lemmy.world 3 points 20 hours ago (1 children)

Really depends on what you mean by passkey, since it's actually a fairly vague term for a bundle of technologies.

I don't really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.

But I'm a big fan of hardware 2fa using non-resident keys ("passkey" lite); I'll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.

[โ€“] Natanael@infosec.pub 2 points 12 hours ago

Even pw synced passkeys at least have the benefits of both being phishing resisting + replay protected, as well as being able to use the TPM chip for extra local protection.

Hardware keys are logically simpler though