Passkey is some sort of specific unique key to a device allowing to use a pin on a device instead of the password. But which won’t work on another device.

Now I don’t know if that key can be stolen or not, or if it’s really more secure or not, as people have really unsecure pins.

    • V0lD@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      2
      ·
      1 year ago

      Hi, yes, I am that minority

      I have a 37 character password with both cases, numbers and special characters to login to my pw vault using long random strings

      My phone has a swipe pattern lock since that is the safest lock option it allows in the first place. I wish I could lock it better, but the only other options available to me are a 4 character pin, and fingerprints/facial scan. I hope the problems with those are obvious

      Couple that with the fact that I have a daily predictable commute in public transit where I have a habit to put my phone next to me during breakfast and you have a recipe for disaster.

      • GreyBeard@lemmy.one
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 year ago

        Finger prints on Android stop working after 24 hours, a reboot, and some other cercumstances. I feel pretty OK using fingerprint to unlock my phone, because in about 99% of cases I might be compelled to unlock my phone, I will either be able to restart it first, or that 24 hour timer will have expired.

        • V0lD@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          I have MFA in addition to that pw, yes

          There are better phones out there.

          That’s news to me. Which other mobile authentication is there besides pin, pattern, facial and fingerprint?

        • hedgehog@ttrpg.network
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 year ago

          Even FIDO2 MFA doesn’t protect you from attacks that involve malware running on your machine. If there was a keylogger on their machine then that machine is likely compromised in other ways, and any credentials entered or stored on it should be considered compromised and should be reset.