Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have been using passkeys for a while in the form of yubikeys

Best practice is to register two keys to every website. Keep one physically in a safe.

With password managers I would say the same basic practice applies. Make sure you have a working offline backup of whatever secrets you hold dear.

There are some sites that only allow you to register a single passkey for an account (AWS Console last I checked) but these should be getting fixed as it becomes more popular



> Best practice is to register two keys to every website. Keep one physically in a safe.

Well, this sounds convenient. Keep the second one in a safe, but register a key to it for every website you use.

Is this a practice we actually believe users will carry out?


Yubikey are $50 so if you are already investing real money in your online security it’s not a stretch to expect that people will spend extra time and money to keep a physical backup

I don’t bother with a safe. I have one key that never leaves my home desk and another I have on my keychain. It’s trivial to register the second key when I am home.

Yes it is less convenient than a digital passkey but there is absolutely no way for a remote attacker to compromise it




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: