Post #382562
2026-02-12 10:07 UTC
Replies (5)
-
@lukasa@hachyderm.io 2026-02-12 11:43
@ericholscher@fosstodon.org I’ve used them for some personal sites that I had to make Internet-open for various reasons. They’re pretty ok!
-
@b0rk@social.jvns.ca 2026-02-12 12:43
@ericholscher@fosstodon.org i’m using them for a few sites and storing them in 1password. sometimes it doesn’t work but i can always just use a password in that case
-
@carl@social.lol 2026-02-12 14:19
@ericholscher@fosstodon.org I haven’t really adopted them (partially from not really understanding their limitations) but I was pleased to see they can be shared in a 1Password vault. It seems like interesting tech with a poor PR team.
-
@glyph@mastodon.social 2026-02-12 16:22
@ericholscher@fosstodon.org have been using them for years on tons of sites. 1. make sure you understand how fallbacks and alternate auth methods work on every site you enable them on; I haven’t found a site that takes away all your fallbacks and I wouldn’t add a passkey to such a site; make sure you have a totp authenticator too 2. treat any passkey auth failure in a browser as *extremely* suspicious; close the browser and manually enter the URL. apps which don’t support passkeys are pretty common though
-
@douglatornell@opalstack.social 2026-02-13 22:36
@ericholscher@fosstodon.org I too use them for a few sites and store them in 1password. Works fine for me.