Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is a weird take. The passkey can be up to 1400 bits in length which makes it significantly more difficult to brute force than a 256 bit password. Not to mention some sites won’t even let you type in a password that long, and then ofc rainbow tables.

Passkeys are significantly more secure for everybody.



a truly random 256 bit password would require more energy to brute force than the sun will emit during its entire lifetime. a 1400 bit long random password is not any more secure in practice.

Passkeys are normally 256 bit ECC keys.


You’re totally right, more bits doesn’t mean more security. /s

I seriously hope you don’t work in any security field.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: