One thing passkey proponents forget is password-authenticated key exchanges (PAKEs).
PAKEs use passwords, and they are unphishable. That is the direction we should go to avoid vendor lock-in.
PAKEs use passwords, and they are unphishable. That is the direction we should go to avoid vendor lock-in.
It does handle the second and third, IIRC.
Passkeys work because the user can't be tricked into entering their private key on a phishing website.
This is why I keep a spare.
You can pay a locksmith to pick (and rekey) the door lock. You can even break down the door and replace it later. None of that is an option with passkeys.
Ah, the magic of having two of them! Truly a revolutionary experience.
I just used my physical tokens or my laptop or desktop to authenticate my new phone.