Makes me all feel like passkeys are largely a convenient security excuse for vendor lock-in and siphoning personal information. OTP-Generators seem to be more generally applicable and less phone or company-bound.
Makes me all feel like passkeys are largely a convenient security excuse for vendor lock-in and siphoning personal information. OTP-Generators seem to be more generally applicable and less phone or company-bound.
On Windows, macOS, iOS, and Android, there's a cloud-based password manager built into the operating system, so you can use your passkey anywhere you use that password manager.
Microsoft, Apple, Google, 1Password, and Bitwarden all have password-manager apps for Windows, macOS, iOS, and Android.
Pick a password manager and use the same one everywhere, and your passkeys will be available wherever you go.
And I think for FIDO2 keys, this is fine. If I can register a key (plus a backup) the usage doesn't seem so different from a regular key.
For the rest, I think what irks me is the feeling of "you have free choice which corporation you want to entrust all your login credentials with, but you will have to choose one". Previously, password managers were a convenience (that incidentally also increased security, because they made keeping a separate, hard password for each domain practically feasible) - but nothing stopped me from keeping passwords at several different places at once or memorizing some of them, in case I lose access to the password manager.
Now suddenly, they become the arbiters of my logins everywhere. What happens if they ban me, or go out of business or get bought up? (Or in Apple or Google's case, make arbitrary business decisions that can now affect the way I login to completely unrelated services?)
Being able to sign in with touchID is amazing
Passwords were a really poor solution to the problem of security, they didn't take the human factor into account. After a rocky start, I'm now finding passkeys super easy and convenient to use. Far more convenient than OTP codes.
I appreciate that if you're OS/browser doesn't integrate nicely with passwords you might be in for a bad time. I'm having a great time with 1Password, though I believe native apple handles them nicely now too – and I suspect this is true of any modern password manager (even the ones built into the browser).
Sorry to attach on to such a small part of your comment. Why do you think having it attached to your phone is worse? In my understanding phones are WAY more secure than any run of the mill laptop or desktop due to a variety of security measures like sandboxing, encryption by default, and secure elements. If I came home to a break in I would be way less nervous about them swiping my phone than my desktop.
It can be distracting. You have social media, messages and apps on the same device you need to login. Already makes it harder to put away the phone for a while.
It can never be "cold": You have your phone always with you, which means the risk of it being stolen or lost is higher than with something you can keep in your desk drawer for 99% of the time.
It's a single point of failure: If you should lose it, you potentially have a huge problem: You're right that a thief couldn't make much use of it and we have sophisticated tech to remote-lock and locate phones now. But that won't help you if you need your phone to log into your Google or Apple account to access that tech in the first place.
(Yes, I know there alternative ways to regain access to Apple or Google accounts, but those all rely on you having something... not on your phone)
I don't really own the phone. I know it's paranoid, but I don't like the idea of some update being able to change the way authentication is done. (Even if this is improbable in practice) At least FIDO2 firmware has a fixed interface.