← Back to context Comment by paulddraper 11 hours ago Passkeys. 2 comments paulddraper Reply jackjeff 11 hours ago Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny. paulddraper 6 hours ago Passkeys are really long password locked to a domain, i.e. no different* than your setup.Passwords are just a worse, hacky version of passkeys.*They are private/public keys, so they can’t be MITM.
jackjeff 11 hours ago Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny. paulddraper 6 hours ago Passkeys are really long password locked to a domain, i.e. no different* than your setup.Passwords are just a worse, hacky version of passkeys.*They are private/public keys, so they can’t be MITM.
paulddraper 6 hours ago Passkeys are really long password locked to a domain, i.e. no different* than your setup.Passwords are just a worse, hacky version of passkeys.*They are private/public keys, so they can’t be MITM.
Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.
I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.
And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.
Passkeys are really long password locked to a domain, i.e. no different* than your setup.
Passwords are just a worse, hacky version of passkeys.
*They are private/public keys, so they can’t be MITM.