Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use passkeys exclusively on my YubiKeys, and I ensure I always have a backup (two Yubikeys with one passkey each).

TOTPs are handled the same way (stored on two Yubikeys).

We used password managers when 2FA allowed us to guarantee that even a leak of the passwords wouldn’t be that catastrophic. If you sync your passkeys to your password manager, anyone compromising it has full access to your accounts.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: