Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

`rk=required` means your hardware is required to store each and every derived key, not just the master key, all in the service of you not needing to remember your username anymore. Current security keys can handle a couple dozen derived keys at most, _if_ they can handle any at all.

This flies in the face of previous promises where 'every key can handle an unlimited amount of accounts'. In my eyes, this looks like a big push towards phones as passkeys, and nothing else. Would fit with the Bluetooth sync strategy as well.



As someone who doesn't and won't ever have a mobile phone, I can't comprehend why things are going in this direction.


Because almost every human who has digital accounts does.


Well, 1984 and Fahrenheit 451 were warnings of the world we are slowly heading towards.


I guess that means passkeys are DoA for me.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: