With PassKeys and push notifications, there’s no way to do that.
With PassKeys and push notifications, there’s no way to do that.
It's unfortunate that passkeys have been such a disaster. Attestation should never have been part of the spec, it should never have been presented as a replacement for hardware U2F keys, and a private key file format should have been defined on day 1. But there is useful functionality buried under all the noise and confusion.
I suspect that many people's Passwords apps are littered with dead passkeys.
And that's another thing: if you use a 3rd party e-mail service then you have to trust a 3rd party not to abuse that. If they have control of that email address they can take over your account. If it's a temporary address, who's to say when that address gets reused?
If you don't use a 3rd party service then you have to have your own domain for that e-mail address, that domain name can then also be traced back to you.
If you want it to be anonymous, you shouldn't use e-mail at all and only allow passkeys.
The issue is that the demographic we Serve (recovering drug addicts) is a very privacy-sensitive one. Another demographic (that we don't serve) is non-hetero/cisgen folks. Both of these demographics can mean persecution, and even death, in some places, so we are not casual at all about the privacy of our end-users.
At the same time, too much security can render the app useless, so we need to find a balance. The issue with information, is that once it's out; it's not so easy to put back in the bottle, so we tread carefully.