Then you register multiple passkeys for the website, just like you would register several Yubikeys.
It’s a 1-click process, and no HW-token required. Most people will be fine.
Then you register multiple passkeys for the website, just like you would register several Yubikeys.
It’s a 1-click process, and no HW-token required. Most people will be fine.
But, its like I said: You have zero concept of the struggle that is already happening and will continue to get worse. That's what I mean when I say that the software industry has zero concept: You think you have the solutions, but you actually haven't even grasped the full scope of the problem.
passkeys are not serious until they actually address backups in a way that isn't just "we'll copy the secrets around in our cloud services just like passwords lol"
(And it's not like there's no solution here: firstly make it mandatory in the spec to allow enrolling multiple keys, then standardise a means to enroll a device from another device, automatically, across all devices that other device is enrolled in, and then also it would probably be a good idea if that also offered a way to revoke the other keys)
this assumes majority of population has the means and discipline to purchase, register and maintain multiple pass keys and/or devices.
There's a world outside the developed countries where a typical yubikey can cost 10-20% of a family's monthly income.
A family where phones are the only tech devices in the household and the phone is typically in a 100-150 USD price range and costs about half of monthly income.
By making passkeys mandatory we are asking them to get multiple of yubikeys/phones per person in the family ?!
They cannot afford to and will not maintain multiple passkeys or backups.
Orgs will have to build a way to help them recover their accounts easily without further costs or just ignore them as "edge cases".
They replace passwords, after all.
So just like Yubikeys, when you lose one of those keys you'll need to go to the 100's of sites where you registered that key and change it. This is not a good plan.
Passkeys do not (and are not intended to) solve the problem of lost credentials.