I will not use them unless there's stronger laws about biometric data and privacy. I realized that the whole point of passkeys is to replace passwords. It won't be immediate, but it is clearly the long term goal. I don't want my secrets/password secured to a ecosystem login. If I don't control my secrets, they aren't my secrets. It's a single hardware point of failure.
If passkeys are made mandatory, I want TOTP/HOTP to be primary and mandatory for every login as well.
In a hypothetical scenario where a government is looking to unlock your data, using a passkey would guarantee them acess to your data since a warrant will let them take the physical key or force you to unlock your device.
"A man must use his fingerprints to attempt to unlock his phone, an Illinois federal district court ordered in signing a search warrant, finding that the request does not violate the Fourth or Fifth Amendment." [1]
The marketing from some companies that it will replace both password and TOTP codes with just passkeys make me wonder the motivation behind this push.
I took time to understand passkeys, and they are essentially a new implementation of the idea behind YubiKey locked behind major corporations like Google. "Your" phone device is a YubiKey that you can add to websites. And just like YubiKeys, they don't allow exporting keys. Worse they are tied to a megacorp login. The attestation requirement is already satisfied in current YubiKeys.
Until an open source "weak" hardware or software implementation of passkeys exists and is clearly allowed by websites, I will not believe that attestation will not block this. Exporting secrets, while possible to code in an implementation, breaks one of the core ideas behind using something like a YubiKey where the assumption is one device per private key. Why would a website willing allow a "weakened" implementation? That would compromise the security model.
I felt like a conspiracy theorist considering how the US government is becoming more of an"authoritarian government" but I realized I was giving the benefit of the doubt to an entity that doesn't deserve it. The US government is becoming agressive in dismantaling people's constitutional rights with technology.
"Once a warrant is secured, the type of passcode becomes the next deciding factor in whether law enforcement can gain access to a phone's contents. Cell phones are typically protected by a passcode that is either numerical or alphabetical, or by biometrics, such as a fingerprint or faceprint.
A Virginia circuit court ruled that police can require someone to give them access to a cell phone as long as the passcode is biometric, such as a fingerprint. That's because a fingerprint is considered something you have — physical evidence — and thus not self-incriminating. Stanford's Pfefferkorn said this can also extend to facial recognition.
But numeric or alphabetical passwords, on the other hand, are often considered something you know. This is where courts are divided." [2]
1. https://news.bloomberglaw.com/privacy-and-data-security/forc...
2. https://www.tampabay.com/business/when-can-police-compel-you...
https://www.governing.com/security/search-warrants-can-requi...
https://psmag.com/social-justice/can-the-government-force-yo...