Comment by Sick-Poster

11 hours ago

It is actually very hard to force password manager usage. You can encourage it, educate, but forcing it? How do you do that.

Passkeys.

  • Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.

    I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.

    And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.

    • Passkeys are really long password locked to a domain, i.e. no different* than your setup.

      Passwords are just a worse, hacky version of passkeys.

      *They are private/public keys, so they can’t be MITM.