Comment on Google will now make passkeys the default for personal accounts

<- View Parent
confusedbytheBasics@lemmy.world ⁨1⁩ ⁨year⁩ ago

Use a pair of hardware tokens and a long pin if you want maximum security. If you want to use a sync-able software token do that and set a strong pin.

You like long passwords? Go ahead and put one on your passkeys. You don’t have to use a short pin.

It is two factor. Something you have, key in TPM or hardware token, and something you know: the PIN. Or if you choose to enable biometric it shifts to two things you have the: key and your face/fingerprint.

Remember you only have limited attempts to guess the PIN and biometric auth is subject to configurable timeout conditions before the PIN is required.

Any security conscious person will use a strong PIN. Many will choose to use biometrics as well for convenience. Most people are still setting their password to Sm3llyK@t42 on every website. A protected key and a 4-digit pin/finger print is a huge leap in security.

source
Sort:hotnewtop