Passkeys aren't a full replacement in my opinion, which is what DHH gets wrong. It's a secure, user-friendly alternative to password+MFA. If the device doesn't have a passkey set up you revert to password+MFA.
cashew
joined 1 year ago
It uses asymmetric cryptography. You sign a login request with the locally stored private key and the service verifies the signature with their stored public key. The PIN on your device is used to unlock access to the private key to sign the login request.
I agree. You can't just dismiss the problem saying it's "just data represented in vector space" and on the other hand not be able properly censor the models and require AI safety research. If you don't know exactly what's going on inside, you also can't claim that copyright is not being violated.
Microsoft Java is a one-liner these days.