• jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      10 months ago

      The non-discoverable keys cannot be removed from the device. The secret is non-transferable.

      In the yubikey bio series, this is implemented as a second factor. So you log in, and then present your hardware key as a second factor. You need your fingerprint, the key, your username. Fairly secure.

      I think this is a more secure model than pass keys as they’re being promoted today