fiatjaf
· 25w
SQRL invented the anti-phishing public key cryptography based approach to website authentication many years ago. It was a beautiful spec of one page with multiple grassroots implementations.
Then the...
Best practice (which is probably rarely followed) is to let users add multiple passkeys to the same account. That said, the level of lock-in they achieved by not letting you export anything and syncing only to a certain ecosystem's cloud servers in all big vendor implementations is completely over the top.
🤙1