Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

what if you sign up a new account somewhere with a passkey? Then, it's the primary authentication method, right?


As far as I understand, this is not a viable mechanism.

Consider a shared computer in a university laboratory or at a public library. Or maybe an iPad that is shared by a family.

As a service provider, you usually can not assume that someone using your service will log in with a dedicated device or with a device that has their primary google or apple accounts setup on it. (Some rare exceptions might exist).

I don’t think anyone wants to deal with customer support problems of “oh, I’m stuck in a different country when on a holiday and my phone got stolen, can you please recreate this key exchange process for me on this untrusted device logged in from public wifi at a coffee shop?”

Like with ssh certificates, you create more problems than you solve if you use passkeys as the primary authentication mechanism.

To answer your question, yes it would be primary authentication if you used it that way. But no sane person would. Hopefully.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: