Comment on Passkeys Explained: The End of Passwords

<- View Parent
3abas@lemmy.world ⁨22⁩ ⁨hours⁩ ago

Say you don’t understand passkeys without saying you don’t understand them…

A passkey uses public key cryptography to secure your account instead of a password, it only grants you access to the one account you set it up for, and the account provider only holds your public key, you control the private key. Your passkey is a secure alternative to passwords because you CANNOT reuse it across services, cannot reasonably remember it, and the method of using it isn’t by copying and pasting into a field like a password, so it isn’t susceptible to the same attacks.

If the provider loses your public key, they can’t give you a challenge to verify you have the private key, so you lose access. Just like if they lose your password hash. It’s an identical scenario.

source
Sort:hotnewtop