I have thus far avoided full lockouts because I have obsessive, methodical backups to my backups for authentication on pretty much every site, but this kind of failure mode is close to metastasizing into folkloric βnever use passkeys, you will get locked outβ peer education, and once that happens, it is never going to recover. You will have users insisting on passwords for the rest of their lives, content marketing LLM slop repeating this nugget over and over forever
@glyph This is one of the reasons I'm reaallll disappointed that we seem to have decided that discoverable/resident keys === passkeys and you should use them for both user identifier _and_ password replacement, because it makes "recover account if something goes wrong" require a lot more thought
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.cthos.dev/users/cthos/statuses/114456151978775495 on your instance and quote it. (Note that quoting is not supported in Mastodon.)