1
Passkeys and/or TOTP, aka real 2FA that isn’t tied to email
G
GeneBean
Oct 22, 2025

Please allow passkey login. My account shouldn’t be constrained solely by email. Email is not a suitable 2FA method. Username + password + TOTP or email token + TOTP are good, but Passkey is better because it requires a device you possess already and doesn’t rely on email that’s phishable. I’ve seen other sites go further and require TOTP after a Passkey too, fwiw. Point being, give uses the option for real 2FA decoupled from email.

This is from https://primal.net/e/nevent1qqs2zesra59y63vh6422tgr2rg08g8w0z54f9gd7h0r9cex9z6ml0vcz24327 as requested.

Comments
No-one has commented on this post yet.