Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly?
Why would you trust the very same password managers that don't handle passwords properly to handle passkeys properly?
I'm not sure why you're making a distinction. In many cases the browser is the password manager.
Password managers have had to be permissive enough to work with most websites, and there is no standard for it. There have been sites that blocked the autofilling of passwords and so on as well.
My point wasn't this one particular flaw in some password managers is the reason to use passkeys (the copy/paste point is the much bigger issue anyway), just that it's an example of how relatively brittle the password manager process is. Having it a core part of the spec gives stronger guarantees.
Sites that do this irritate me so much. Ones that try to block pasting and stuff… like somebody intentionally baked that into the site. Who? And what was their rationale? Are they really so arrogant to think people are going to carefully type in some elaborate password not once but twice?
That and blocking paste in fields like bank account numbers and stuff.
Surely somebody here has been asked to implement these mis-features. Please explain what went through the heads of the people responsible for it?
There's no real regulation requiring blocking paste but it has become an annoying informal standard of sorts.
The passkey integration goes the other way, which is much more reliable.
Gell-Mann amnesia effect
https://en.wikipedia.org/wiki/Michael_Crichton#%22Gell-Mann_...