Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh, ok. If that's the same thing as passkeys, then I finally figured out that I'm not interested. To me it looks like another vector for platform lock-in, or getting mysteriously locked out of my accounts with no recourse. I'll wait for FIDO3.


Yep. I absolutely refuse to support anything that wants to dictate what I do with my identity.

Such things do have purposes, in high-stakes environments. They prevent accidents. The vast majority of uses on the public web are not even remotely in that realm. It'd be better off being a separate spec that only a handful of internal-only systems use, ideally requiring MDM to set up conveniently (to strongly discourage normal and even high-stakes-normal website usage).

My banking website has absolutely no business knowing and being able to approve or deny what brand my authenticator is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: