• ricecake@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    6 hours ago

    Depends on the system. The thing where your password manager is managing your passkeys? That’s a single factor unless it’s doing something tricky that none of them do.
    When it’s the tpm or a Bluetooth connection to your phone? That’s actually two factors, and great.

    • Appoxo@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      1
      ·
      1 hour ago

      Can it be copied from your phone? (e.g. by migrating your phone via a backup)
      Then it can be compromitted and is essentially a single factor (because some website permit you to login via the key only).
      Only if you’d need to completetly renew the key, then it’s truly secure.