Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another decent solution is to seed the key, and keep the seed written down or in your password manager. Though I only know of the hacker version of SoloKey that lets you do that. Now you've got the convenience of passwordless login, and the peace of mind that you can always get a new spare.


This is an excellent idea, and I'm still waiting for BitWarden to implement soft-WebAuthn. That way I can just unlock my password manager (or, really, type in a passphrase that will generate the private key) and my browser can take care of all the authentication.

No need to store passwords, you can securely have one password for all sites. You lose the ability of rotating it if it gets stolen, but it's unlikely to get stolen if you never enter it anywhere else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: