Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I understand many passkey complaints but not this one. Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords? You collect and verify an email address at signup and the account can be recovered in the same way as with passwords, or passwordless-email. No CS-verified recovery needed.
 help



> Why, for you as a service provider, are passkeys not just better (or at least equivalent to) passwords?

Why you missed the last line of my answer? How did you get an impression to go back to broken passwords?


All right, my framing was a little too tight. Sure I can see why an email/SMS passwordless loop is easier for you, but it’s a more annoying user experience than your OS/browser/password manager just filling in your credential directly.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: