This is what makes passkeys nonstarters for me.
This is what makes passkeys nonstarters for me.
i regularly use a yubikey as a passkey, and it's entirely orthogonal to any password manager i use. it happily just works on firefox on both mac and linux.
to use a passkey, you need a place to store the passkey. that can be a hardware token, a tpm, or a password manager.
Doesn't this already make that scenario a nonstarter? I can't revoke individual keys if I can only register one key in the first place.
Side note: I feel like people always say 'i can just use good passwords' and then their password is like '<sports reference><year>'
My point being, there is a reasonable limit to how many physical passkeys a person would make but there’s also a non-zero possibility that a physical catastrophe could occur that destroys all the passkeys.
What happens in that case? Can you recover your accounts?
If you still have your passwords after your house burns down you can use those to get into sites.
If your house burning down also wiped out wherever you store your passwords, you'd use whatever mechanism each site provides for recovering from a lost password.
Also, it's not always convenient or possible to plug something into a machine you're using.
> to use a passkey, you need a place to store the passkey.
Yes, and any place that requires me to use particular piece of software, machine, or device is a real friction point for me.
Not many apps support passkeys, but for the ones that do, it's a godsend. No longer do I have to worry about whether my password is stored in Google, or Firefox, or if it's up to date, or what happens if I get hacked. I just plug my little key into the computer and tap it.
It's like having a physical key instead of having your password written in a page of an obscure book in the library. Probably safe, but someone dedicated can find it. A physical key can only be taken if my house gets robbed.
You never have too worry about it with a password manager, and also don't need to worry whether your key is plugged in in the computer you're currently using
Once Google and Firefox start pushing their passkey implementation, you do. One issue with them is user confusion about where the passkey is stored.
And do you have a backup solution for if you lose your physical key? That's the big problem I have in practice at the moment: I would like a physical device for storing credentials, but I 100% cannot have it as a single point of failure. Unfortunately at the moment it seems like I either have a cloud sync vendor lock-in or a single point of failure, or I have the completely impractical solution of enrolling multiple devices, which means I have to carry both around with me, thus making it far more likely I lose both of them!.
• You can use multiple independent cloud sync vendors. When I add passkeys to an account I add two passkeys. One gets stored in 1Password and synced using their cloud. The other gets stored in Apple's Password and synced using Apple's cloud. This should give you enough redundancy to mitigate most vendor lock-in concerns.
• If using devices that don't cloud sync I don't see why your would need to carry around two devices in order to enroll two devices. Carry around one device, and when you make a new account create a passkey for that account stored in the device.
Later, back home, login into any accounts you created while away using the passkeys on the device you were carrying, and create a second passkey on each of those accounts and store it on the other device.
The thing is, this seems like an entirely solvable problem, from multiple angles: e.g. an end-to-end encrypted sync between devices (using some pairing process), or, even better, a way to enroll a non-present device as an alternative (though this has some of its own challenges, if not just using a persistent certificate). It suprises me a little that there's nothing that really attempts to address this.
Apple is adding that in iOS 26 and MacOS 26 [1], based on the FIDO specification for this [2].
Google is also in the midst of implementing it [3].
[1] https://fidoalliance.org/9to5mac-apple-work-passkey-portabil...
[2] https://fidoalliance.org/specifications-credential-exchange-...
[3] https://fidoalliance.org/mobileidworld-google-developing-pas...
It took forever to make any movement towards getting people to stop using the same password every where. Now we're telling people passwords aren't secure even with using a password manager and they should use passkeys. So now we're saying that using the same software that we spent so much time suggesting to use is not good enough. Instead, now you want them to use a dedicated piece of hardware that needs to never be lost, but people lose their phones frequently.
It's amazing to me how the majority of readers here absolutely cannot put themself in the place of non-computer nerds that spend 0% of their day thinking about code/security or anything other than what the Kardashiens are doing or their favorite influencer or whatever other nonsense that is everything and not nonsense to them. It's this kind of thinking that put us in this position that the people building the thing can't think about how the users will actually use it
The ability to migrate them was considered an optional feature and not implemented before they were launched. It's still wholly unclear whether any individual implementation will let you do that or not, with options to prevent it.
I’ve seen enough horror stories here that this can’t be handwaved away.
Another feature of the password manager.