What’s your opinion of Passkey vs. 2FA (password plus physical token).

I’m skeptical of passwordless Passkey, but want to hear other opinions.

Reply to this note

Please Login to reply.

Discussion

I consider them less secure than non-synced 2FA codes in an app,

Which I consider less secure than an air-gapped device like a Yubi.

I do use them though, for accounts I consider less secure. For instance, any company that requires a SMS backup for 2FA, you might as well use a passkey because it’s more convenient and you’re only as secure as SMS anyways.

What does “non-synced 2FA” mean in this context?

Any 2FA app for a phone or PC that does not have cloud sync.