Hacker News new | past | comments | ask | show | jobs | submit login

For 500 accounts you would need 20 yubikeys. That’s quite a yubikeyring.



True. I personally prefer non-residential keys that don't take up any space on your yubikey. The keys are reconstructed on the fly based on a value that I receive from the server I am authenticating against.

Passkeys are residential keys and they consume storage. The minor upside is that they free the user from remembering their username.


The other upside is that you can store them in either HSMs or software-backed stores (password managers) or hybrids (like your phone). It's trade-offs all the way down!


Can't you do the same thing with non-residential keys?


You can. But then you miss out on credentials discovery.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: