logoalt Hacker News

akdev1lyesterday at 9:11 PM1 replyview on HN

By still having the password the user can still be attacked via phishing


Replies

thewebguydyesterday at 9:36 PM

The user can always be attacked via phishing so long as account recovery methods exist (and they need to exist for obvious reasons). Use passkeys, but so long as you can also log in via password, or SMS code, etc., it's phishable, you can get sim swapped.

Your master password to your cloud PW manager's vault is also phishable (hence why passkeys were ideally device specific, non-exportable).

Its phishing resistant not phishing proof

show 2 replies