> Maybe I am getting old but password+yubikey/webauthn was really top UX.
It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...
The creds they store hold no value. These creds only give access to their system anyway. They store the email address either way so the situation is no better but less convenient.
They hold no value precisely because they don't store them and send you a magic link! If they stored a recycled password or its hash, then it would be valuable.
Not sure this is what I meant. Password is still stored, along will all the keypass stuff. If you have the option to login with the keypass... or the password - possibly sending you a link (or code) to the email.
blfr · · focus · HN ↗
mschuster91 · · focus · HN ↗
It most definitely isn't. Any 2nd factor that is not the device I am currently using (either a yubikey or my phone) has a non-zero chance of not being near me when I need it, leading to the constant question of "where the fuck did I put that darn thing", only to find out that the cat has decided to believe the yubikey is a mouse and tried to devour it, the phone's battery went dead...
xxs · · focus · HN ↗
blfr · · focus · HN ↗
esafak · · focus · HN ↗
blfr · · focus · HN ↗
esafak · · focus · HN ↗
blfr · · focus · HN ↗
xxs · · focus · HN ↗