Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A lot of people only have a phone these days. It's way more likely that they lose their phone than their home burns down.

In Microsofts case they want to use passkeys for Outlook.com as well, so their advise on using an email as recovery makes no sense. Then you can use security questions, which honestly is possibly worse than username and password. The last option is via a linked phone number, which security experts also advise against.

My complaint about passkeys stand, without non-digital way of backing them up, as easy as writing a password on a post-it and stuffing it in your sock draw, it can see it being anything that a major hassle.

For some things, e.g. Github, Facebook and things of that nature, fine, go with passkeys. For your email account, may not.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: