Yeah, except if we're talking about web development, then the lower layers is not Raylib. It's HTML, CSS, JS with its DOM API, plus whatever other bullshit WhatWG throws in.
So passkey is saved to my account. Account is logged in on multiple devices, secured with an additional pin.
It doesn't matter what device I'm on, I can either use the app on a mobile device or a browser.
Site goes to login, prompts me for passkey, I type in PIN and select the passkey from my password manager.
It's fast and easy to use.
If I am on a random device (which never happens, ever) I would just log in via browser, or use one of my hardware tokens if I were expecting to access something from an unusual device.
Sometimes I need to sign in to a personal Github account on a work laptop, so I hope non-passkey flows keep working. I don't install my personal password manager on a work laptop.
For a 20-character password to be strong, you pretty much need to use random characters; you cannot use the superior “correct horse battery staple” approach as you’d be limited to two words, which isn’t very secure.
reply