This would be quite bad from usability or privacy pov, I guess.
This would be quite bad from usability or privacy pov, I guess.
It's completely insane to treat a credential to an account as something that cannot be backed up. It implies there's another form of recovery, which likely means that key is only as secure as the other recovery options. And when it comes all the way back to the master key to your manager itself the loop falls somewhat apart.
It's a hard problem, but passkeys aren't ready for me yet.
This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to move credentials between vendors/ecosystems, without opening end-users up to phishing attacks on credential export.
If big tech wanted to lock people in, it seems like it would have been a lot easier to just... not create an open standard.