WebAuthn FIDO2 Security Keys
Comments advocate for WebAuthn, FIDO2/U2F, passkeys, and hardware tokens like Yubikeys as superior, phishing-resistant authentication solutions compared to alternatives like TOTP or SMS.
Activity Over Time
Top Contributors
Keywords
Sample Comments
Why don't people just use webauthn?
It's mostly WebAuthn isn'it it?
It's what FIDO/U2F does, right?
Sounds like a good use case for fido authenticators or passkeys.
Yubikey, FIDO2, etc already exists, though not supported everywhere.
With WebAuthn it doesn't have to be a USB fob - it can be built into your device too.
Don't all fido2 yubikeys support webauthn? They have the advantage that they can't be cloned/sync/etc. Might be an inconvenience for some but for me that's an advantage.
Yes webauthn is a much better solution to this.
For chrome u2f was replaced by webauthn. Regardless, both are hard to implement compared to passwords
FIDO2 Security keys should be considered good "hardware tokens" now , more phishing-resistant than TOTP