Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Passkeys are still a shared secret, aren't they? Asymmetric cryptography would have been amazing. Barring that I would actually recommend Oauth or something like it, to limit the number of parties who manage shared secrets to a smaller set of actors who have more experience doing so.


They are in fact public/private keys and use signing a challenge for authentication.


But in practice they usually rely on attestation by an approved vendor, and the vendor won't let you control your private key, so they'll leverage it for lock-in.


No, they're just resident webauthn credentials which use asymmetric crypto.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: