2026-09-08 17:46 UTC
@drsbaitso@infosec.exchange And this is more important than having phishing resistant authentication?
The reason I ask is that I'm a security engineer tasked with helping protect accounts like yours. What situation would you start using passkeys?
Replies (1)
-
@rickhunter@infosec.exchange 2026-09-08 18:13
@Xavier@infosec.exchange @drsbaitso@infosec.exchange A website should never tell the browser to accept a passkey without the user explicitly requesting to create it. Good: My pharmacy notices that I don't have a passkey after logging it. It asks if I want to create one now and respects my decision if I decline. Bad: Amazon spontaneously telling my browser to save a passkey when all I've done is open my Order History page. That passkey dialog should never pop up by surprise, in the middle of an unrelated workflow.