Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What if your device cannot connect to internet? OTP can work even if device is offline.


If your device has limited network connectivity, it can create new passkeys or use a passkey it already has for interacting with a service. However, it won't be able to synchronize new credentials with any cloud service in multi-device scenarios.

Or in other words, it works the same as a password manager today.

There is a slight wrinkle that some platforms may eventually offer to use an internet service during registration for any required device attestations (e.g. no, this is really coming from mobile phone brand X). Your registration process can't require such things if you are dealing with non-internet-connected devices.


The passkey lives on the device you are logging into the service with, so it implies you have internet access there to be able to log into it in the first place.


I guess you're specifically referring to TOTP or SMS-based OTP. Email OTP still requires an internet connection, for example.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: