• @jetA
    link
    English
    1
    edit-2
    8 months ago

    I prefer the yubikey webauthn fido2 non passkey approach. It’s not limited to 25 slots. And if your key gets compromised, or you’re forced to unlock it, there isn’t a list of sites that it works on.

    With passkeys, if somebody compromises you, physically, they can see everything you can log into. That makes me feel icky

    • NaN
      link
      fedilink
      English
      48 months ago

      There are definitely pluses and minuses. It will lock you out after 8 incorrect pins so if it came down to it, you could probably force it to lock pretty quickly.

    • @tippl@lemmy.world
      link
      fedilink
      48 months ago

      if somebody compromises you, physically, they can see everything you can log into

      Can they though? I own a few yubikeys with passkeys stored inside and i cannot query stored logins without entering a pin.

      • @jetA
        link
        English
        -18 months ago

        Right, so they coerce you to unlock the yubi key (threats, torture, finger removal, etc) and now they see all your passkeys and what they belong to. It’s a menu of your activity.