Protect what matters – even after you're gone. Make a plan for your digital legacy today.
Forum Discussion
telephoneman2
3 years agoSuper Contributor
What is from software perspective difference between passkey and Physical FIDO2 Hardware Key?
Hey guys, what is the difference between a passkey and a HW key. Some websites like Facebook or even 1Password.com already offers to add FIDO2 compatible HW keys as 2nd Factor (not for primary login,...
Anonymous
3 years agoWhile the article from Yubico is very comprehensive and contains great information, it is strongly biased towards the use of hardware keys. Most certainly because their business is the selling of hardware keys, and if people realize they can just start using passkeys without a hardware token, they lose their business.
I'd like to comment to slightly bias to the software side of things. From a security point of view, the use of software passkeys is slightly less secure than the use of hardware keys. However, not prohibitively less. The use of a hardware key is more inconvenient than the use of software passkeys. There's more to it than just touch that button of a hardware key. If you lose the hardware key, you have a problem. With cloud synced software passkeys, you cannot lose the cloud. It's also not very probably your software passkeys get compromised/stolen. That requires a direct attack (hack) to you. The same can happen to your hardware token. A thief could steal the token from your USB port while you're looking away. That's different. What type of key is more or less secure or more or less convenient for you depends on your personal environment and use cases. They are both equally valid alternatives.