Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

  • cenzorrll@piefed.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 days ago

    I’ve found a pretty good use for a passkey. Docusign. About every 3 months I need to docusign something at work. The process involves logging in, changing your password, logging in again, opening the document, logging in to sign, logging in to finish. The only steps you get to skip if there’s more than one document is the initial log on, and changing password. So with a passkey I just touch it a bunch of times and there’s no password change.

        • bookmeat@lemmynsfw.com
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          2
          ·
          10 days ago

          There’s like a million other free/libre digital document signing platforms out there. Try one that doesn’t suck.