Next day the phone broke, and I lost that account forever. I had not written the backup codes down anywhere.
https://www.computest.nl/en/knowledge-platform/blog/advantag...
Passkeys are significantly more secure for everybody.
Passkeys are normally 256 bit ECC keys.
I seriously hope you don’t work in any security field.
- Passkeys give the website no secret to keep.
Breach of the passkey public key is not an event worthy of credential rotation.
- Passkey authentication is submitted via a rigorously-defined mechanism intended for machine-to-machine communication.
Ever had your password manager try to fill the wrong field with your login credentials? Passkeys cannot make that mistake. There's no heuristic mechanism at play trying to figure out where to insert the passkey.
- Passkeys are immune to credential theft via MITM
Sure the MITM could hijack the session, but not the credential. (I know this one is a stretch, but you asked for anything)
But then if you DO have it, you have to deal with the situation in this story, where if you can compromise their one key account, you get all of their TOTP codes too.