1. All sites/services would allow the registration of 5 or more keys, which can be tracked/revoked separately. That way if one device is stolen, you can invalidate that key without affecting others.
2. There are two sets of keys: "Regular Use" and "Backup/Recovery".
3. Attempting to use a Backup/Recovery key prompts to user to confirm that they want to invalidate the Regular keys and promote the backup key(s) to the new regular. In this way, a compromised backup cannot be used in secret.
The actual reason is people have many devices. I assume this is at least somewhat common, but I still avoid passkeys so IDK.
You're designing a system where we should just be able to backup our own keys if we want to.
To my understanding both Apple Passwords and the Android equivalent allow you to export passkeys to a different app (password manager), but I haven’t tried it yet.
If anyone has direct experience I appreciate to know how it was.
Last I heard this was a major point of contention between two groups, and last I checked, both had extremely valid concerns.
> Multiple passkeys
I commonly have two software and two hardware keys registered per site.
I feel like all of the security of passkeys could have been build in a compatible way with new standards and enhancements to existing password interactions.
Easy and Secure are often at odds.
I am using a password manager, I have a passkey saved in it. Should that service go down or have some kind of software problem with that passkey, I have physical ones which also can work for offline services such as my OS logins.
"Okay, my password manager is now a program. Oh no, program won't run. Not sure why!"
"Glad I have these physical passkeys! Also helps with those airgapped servers at work!"
This would be quite bad from usability or privacy pov, I guess.
It's completely insane to treat a credential to an account as something that cannot be backed up. It implies there's another form of recovery, which likely means that key is only as secure as the other recovery options. And when it comes all the way back to the master key to your manager itself the loop falls somewhat apart.
It's a hard problem, but passkeys aren't ready for me yet.
This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to move credentials between vendors/ecosystems, without opening end-users up to phishing attacks on credential export.
If big tech wanted to lock people in, it seems like it would have been a lot easier to just... not create an open standard.