Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You don’t need to share them because you can enroll more than one for a given account. So for example if 3 people are sharing an account, you can enroll 3 passkeys for that account and they each have their own access.

I don’t see any way that passkeys kill account sharing.



What the other user says is that maybe those companies will only let 1 device per account to be registered. So you can’t have 2 devices to login. Harder to share.


In this case, Google, that isn't true and just they're mostly treated as special Security Keys ("yubikeys" etc).

To limit it to just one defeats the purpose of all this work. You really will only see that where there is a technical limitation (like... why does AWS only allow a single hardware key per user? If you setup SSO then you can have any number of keys)


Hey, shhh, new thing bad! Get with the program! Not enough fear mongering and too much rational thinking.


It's not fear mongering to have and express concerns about a technology. Especially a technology that many people want to force everyone to use whether they want to or not.

In fact, it's important that people do this so that the invalid concerns can be put to rest and (hopefully) the valid concerns can be mitigated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: