• Appoxo@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    4 hours ago

    To me they seem
    A More user friendly
    B Abstract away the burden of keeping the mTLS synchronized across devices
    C Can be used in hardware and software.

    Feel free to correct me if my assumptions are wrong.

    • majster@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      Is your B point properly addressed by Passkeys? With all this talk about export I presume not. Client certs seem abandoned, you can’t use it on mobile.

      • Appoxo@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        20 minutes ago

        In theory yes.
        Hardware tokens are bound to keys
        Software baes tokens can be synced with password managers (3rd or 1st party)

        And the client cert abandonment problem is an entirely other issue.