I prefer passwords precisely because passkeys have achieved their design objectives. They are just not objectives that I share.
https://mobileidworld.com/apple-introduces-cross-platform-pa...
Absolutely. The problem with narrowly targeted security measures is they are a poor fit for nearly everything.
I'm typing this on my Firefox remote app. Everything is cached in it. It runs in a VM at home.
I suppose I am simulating having just one device.
> It actually sounds like the best way to use passkeys and still have control over them.
I belatedly recall that I tried to setup a Google passkey in a VM and was rebuffed. Google depends on Windows Hello for passkey presentation prompts - and Hello is disabled in an RDP session (ostensibly because facial rec won't be needed).
I poked at the problem for a while and couldn't find a workaround.
It is secure.
> it is not safe,
This is incorrect.
> it's fragile
This is incorrect. Many thousands of sessions over most of a decade all testify to to it's robustness and reliability.
> I understand avoiding unnecessary single points of failure is not for everyone.
That's an interesting segue.
Hm, so then i need one for my account and one for every device where i use this account
> and b) stored on the device's secure enclave, where in theory you're never supposed to be able to export/exfiltrate them, only validate them
i heard that the new "device's secure enclave" is the cloud.
The WebAuthn _also_ allows device-bound keys, but they are not "passkeys".
True. WebAuth is good fit for a login that's tied to a user - and that user only logs into it from their workstation and maybe a laptop. There are better options when more flexibility is needed.
Happily, there are enough secure options that my phones will always be authenticator-free.
That seems to be counter to everything else I've heard about it so far. If that was the case, exporting would be easy, yet many password managers have had open feature requests for some time (1y+?).
I don't know what the truth is, but if you're right, there's definitely a lot of misinformation about it. Far more than correct info IME.
What is missing is the standardized interchange format for exported passkeys.
For example,
And password managers like BitWarden only allow encrypted export, but the encryption key is specified by the user. So you can trivially decrypt the exported data if you want.
No batery, no authentication.
Why do i need an additional device ? A device controlled by another vendor.
This is literally the opposite of what Passkeys are.