•  m-p{3}   ( @mp3@lemmy.ca ) 
    link
    fedilink
    1211 months ago

    If you’re using a hardware token like a YubiKey then you do need to enter your PIN before being able to use it.

    The main benefit is that you cannot extract the Passkey from the secure element (the token cannot be transformed from what you have to what you know) and it cannot be phished through a fake domain as the challenge-response will not match.