Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think skipping 2FA is a benefit. Sure, replace SMS with passkeys or TOTP or literally anything else, but don't actually take away my second factor, please!


Having to pointlessly copy aroudn TOTPs from the same device is just security theater. There's no meaningful security difference for 2FA whether you actually need to copy around those tokens or if you click "authenticate with the key in app on my second factor device".

It's still 2 factors. Just with less hassle (and resulting in more security due to better UX).


Skipping SMS is an obvious benefit. Your passkey management system can embed as many factors as you want.


Placing a bunch of factors into 1 system is a giant SPoF like storing TOTPs with corresponding passwords within the same password manager. It defeats the whole purpose of 2+FA.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: