Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
GitHub doesn’t need to know that - I think that’s why it’s a bit of a cop out for MFA. Sure, your bitwarden may implement MFA, but just a chrome browser isn’t MFA.
Passkeys enable sites to offload the responsibility of securing accounts to the user, and if the user chooses a weaker way to implement them, GitHub doesn’t give a fuck.
GitHub doesn’t need to know that - I think that’s why it’s a bit of a cop out for MFA. Sure, your bitwarden may implement MFA, but just a chrome browser isn’t MFA.
Passkeys enable sites to offload the responsibility of securing accounts to the user, and if the user chooses a weaker way to implement them, GitHub doesn’t give a fuck.