I don't like passkeys | Ethan Hawksley
Ethan Hawksley
I don't like passkeys | Ethan Hawksley
Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
Yeah, this is the key. Distributing your own cert catalogues on a system level negates this issue. But then also that needs to be managed.
But key signing is essential anyways and I’ve often thought the CA system could be used outside of the client to server signing process.