I'm talking about passkeys, powered by the dmzx WebAuthn Passkey & Biometric Login extension. And here's my take: this isn't just another option; it should be the default and eventually, the only way users log into our boards.
Why such a strong stance? Because passkeys solve practically every password-related headache for both users and admins:
- No more forgotten passwords: Think about the support tickets you get for password resets. With passkeys, that practically disappears. Users just use their device's built-in authentication (fingerprint, face scan, PIN) – something they already do countless times a day.
- Phishing resistant: Passkeys are tied to the specific site. A phishing site can't trick a passkey into authenticating, making your users much safer.
- Superior security: They're cryptographically strong and unique for every site, eliminating password reuse vulnerabilities entirely.
- Effortless for users: The experience is lightning-fast and intuitive. No typing, no complex characters to remember.
Here are some key settings I recommend considering:
- Enable passkey login: Obviously, this needs to be on. Let users register passkeys and log in with them.
- User verification: I lean towards Required. This ensures users confirm their identity with biometrics or a PIN when registering or using a passkey, adding an extra layer of security that's still incredibly convenient.
- Remember me for passkey logins: Setting this to Always remember passkey logins can really enhance the user experience, especially for those who visit frequently.
- Maximum passkeys per user: The default of 5 is usually fine, but you can adjust it if you have users who might use many different devices.
What are your thoughts? Have you enabled passkeys on your board, and what has the user adoption been like?
