Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The article praises passkeys for not even needing email for login, but omits to mention recovery flow. How do you recover your account if you lost your access to the passkey provider, and you didn't provide an email address?

So, I think "not even needing email" is unlikely for foreseeable future, unless we find other ways to authenticate people reliably.



The article glosses over much more than that. Everything towards the end feels like provided talking points without the same scrutiny that the current situation is given.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: