What’s your opinion of Passkey vs. 2FA (password plus physical token).
I’m skeptical of passwordless Passkey, but want to hear other opinions.
What’s your opinion of Passkey vs. 2FA (password plus physical token).
I’m skeptical of passwordless Passkey, but want to hear other opinions.
I consider them less secure than non-synced 2FA codes in an app,
Which I consider less secure than an air-gapped device like a Yubi.
I do use them though, for accounts I consider less secure. For instance, any company that requires a SMS backup for 2FA, you might as well use a passkey because it’s more convenient and you’re only as secure as SMS anyways.