logoalt Hacker News

figassisyesterday at 6:45 PM1 replyview on HN

I'd like to think I am pretty security conscious, but I still don't get the obsession with magic links (and passkeys). This is the one thing where I think I disagree with most of the industry. I thought forgetting passwords was a solved problem. I thought 2fa is much faster than searching for the last email for X provider the maybe takes 1 minute to arrive, requires retries and high tend up in spam? Some one please help me get on board.


Replies

essephyesterday at 8:19 PM

Autofill of password manager creds is an attack vector.

Passkeys and email links prevent things like: clipboard interception, malicious iframes, fake login UIs, etc.