Stranding private keys in clone resistant secure enclaves has unacceptably bad UX for the average user, which is why very few implementations try to do that.
Stranding private keys in clone resistant secure enclaves has unacceptably bad UX for the average user, which is why very few implementations try to do that.
Let's say eBay asks user to login. With passkey. Press and hold fingerprint etc. login done. Even with laptop.
And average Joe doesn't want to maintain a keepassdatabse sync it. Yes, you can always use your own server etc but others have life.
That is the reason: for the average Joe not having exportable passkeys is good.
Average Joe doesn't have to do backup. It is all automatic.
The main point is the average Joe it works seamless. And average Joe won't have to remember things.
Yes, it does. Not everyone wants to maintain password database.
Password managers make it easier to avoid those pitfalls, but passkeys make it nearly impossible to fall into them.