logoalt Hacker News

jimbokunyesterday at 8:32 PM1 replyview on HN

Seems like the flow should be:

1. All passwords stored in password manager. 2. Login with password manager when logging in for the first time on a device. 3. Combination of OS and site/app notice that no passkey has been created for this account and offers to create one. This is presented to the user as “setting up the current device for password-less log ins.” 4. OS negotiates with site/app to install the passkey and use it for future log ins on the device.

It’s presented to the user as a convenience clearly tied to this device.

…but you still have your text password stored in the password manager’s servers…


Replies

akdev1lyesterday at 9:11 PM

By still having the password the user can still be attacked via phishing

show 1 reply