• xinayder@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    1 year ago

    This is something being sold in favor of passkeys but I can’t ser how “more secure” it is for me.

    I use Bitwarden, the domain name matching works exactly like passkey’s. How more secure a passkey is, if it has 0 changes to this domain name detection?

    • Natanael@slrpnk.net
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      1 year ago

      With a breach of the server then they can get your password the next time you log in and maintain persistent access until they’re both kicked out and everybody has changed passwords.

      With passkeys you don’t need to do anything, they never had your secret.