Comment on Google will now make passkeys the default for personal accounts
Natanael@slrpnk.net 1 year agoThe main point is all those attacks need to attack the local software or hardware implementation on one of the two ends (or a cert issuer), and even then it’s replay protected so for example an XSS attack lasts only for one session, so it’s more robust.
hedgehog@ttrpg.network 1 year ago
Correct, but that doesn’t change the fact that “Passkeys can’t be phished” is not true.