Passwords suck. Can passkeys replace them?

Lobsters Hottest News

Summary

Discusses the potential of passkeys to replace passwords as a more secure authentication method.

<p><a href="https://lobste.rs/s/oyo7dd/passwords_suck_can_passkeys_replace_them">Comments</a></p>
Original Article

Similar Articles

XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None

Lobsters Hottest

The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.

Switching Password Managers in 2026

Lobsters Hottest

The article explains how password managers can now exchange data across platforms using passkeys, featuring a demo of exporting from 1Password to Apple Passwords on iOS.

New Pass-ta-key attack reveals all the things we didn't know about passkeys

Ars Technica

A new attack called Pass-ta-key shows that passkeys stored in Google Password Manager on Windows can be extracted by malware, revealing that passkeys are generally stored locally rather than in TPM hardware. The article clarifies that this is not a novel attack and that the Windows platform is the main exception.