Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Passkeys are instead of the password. You can still login using your password. This way, you don't have to keep entering your password if you have access to a device with a passkey and can access that device.


Passkeys don't (only) replace passwords – they usually also replace another authentication factor as well.

That other factor might still be available for account recoveries (together with a password or recovery email etc.), but if either are not regularly exercised, users might forget them or lose access to them and not notice until they also lose access to their passkey(s).

That said, Google's and Apple's passkey solutions themselves are cloud-synced (with no way to opt out), so as long as users of either can still access their Google or Apple account, they would not be totally locked out.


Sure, but is that adequate? Not having people practice their passwords seems to be an anti-pattern for selling premium support in password managers, while many other apps ask with planned frequency.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: