What the _% Is a Passkey?
eff.org
eff.org
Until this is fixed, no thank you.
Give me a secure way to make backups on my own infrastructure without the need to forgo my data sovereignty and disaster recovery dependencies to the likes of Google, Apple, etc.
I’m not saying that’s the only (or even main) reason Google and Apple don’t let users make their backups, but explicit non-exportability can be considered a feature in some contexts.
It's good that you can't export a Passkey, which reduce the attack vector against phishing and extraction. It's kinda like how an SSH or a GPG private key should never leave the computer it was generated from, and each machine should have their own unique private key.
Namely, a passkey is something you have- does that mean it can be seized with a warrant the same way your biometrics can be, or the same way papers in a locked safe can be?
I think the answer is yes, Lavabit was famously compelled to produce cryptographic key material.
So 3 points of failure. What can go wrong ?
Password manager support is optional (though at that point you're using a passkey as a re-authentication method, which is nice but doesn't take advantage of the full potential).
That leaves website support. Hopefully more and more web sites will enable it. https://passkeys.directory/ is a list that do.
And if I’m not mistaken, password manager browser extensions should be able to inject their WebAuthN implementation into browsers as well; at least that’s what 1Password seem to be doing on Firefox and Chrome.