• jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    10 months ago

    The non-discoverable keys cannot be removed from the device. The secret is non-transferable.

    In the yubikey bio series, this is implemented as a second factor. So you log in, and then present your hardware key as a second factor. You need your fingerprint, the key, your username. Fairly secure.

    I think this is a more secure model than pass keys as they’re being promoted today