He didn’t have access to it the other day and we needed access to his account. He didn’t remember his password, and we were unable to reset it because you need the passkey! No other options to authenticate for a reset were available.
Add in the fact that I was trying to help him with this by long distance call and you can imagine the frustration.
One of these days the product managers who push these things thinking "oh, it's easy, you just . . ." are either going to be explaining it to confused Mom or Dad, or they're going to be elderly and irritated themselves. Until then I hope they stub their toe or step on random Legos regularly.
Originally it was about difficulty migrating to a new laptop with a different version of Windows, but I was quite firm about it because when I realized it wasn't able to do secure connections for some reason, so the instant they took their laptop to public Wi-Fi...
However the GitHub edition (not Sourceforge) of Eudora2Unix [0] saved me and deserves a shout-out here.
It took some tweaks and a harness to repeatedly try the conversion, since I wanted something I could literally drop into the Thunderbird profile folder. The final result wasn't perfect, (some file attachment issues linger) but it's way better than having it all at risk of Eudora.exe just refusing to launch one day.
Google treats both a password and a passkey as a primary factor, and if you forget either of them you have to go through their account recovery flow: https://support.google.com/accounts/answer/7682439?hl=en
AFAIK there's nothing different about the recovery scenario for a Google account in that state regardless of whether it has a password in use as its primary cred, a passkey in use as primary credential, or both.
Would be nice if Google would lay your recovery options out for you (which I am used to it doing in regard to 2FA if you are doing a regular log in) instead of having to hammer the “Try another way” link repeatedly as it cycles through options.
So, if you are used to the "Try another way" flow on login, it can be confusing to see an entirely different "Try another way" flow on account recovery.
It’s been fine.
Practically, it is a huge challenge. I would want my day to day fob, an onsite backup, and an offsite backup. That’s a lot of hassle and potential for mistakes. To even register the offsite backup means I need access to it. Remotely copying a password database is so much reliable
Also in the process of helping my dad with his phone, 76 and my grandmother 99. Maybe this works better with Apple, but the biggest problem on Android is, that it feels like every update shuffles everything around. Allmost no point in explaining, that they can solve some things on their own.
And all the time new things on the screen, new features they don't understand, need nor asked for.
just hang their heads in shame and walk into the sea
I'd wish the world would just become boring again.
It _is_ true that it's more secure when even the people that the passkey was created for can't use it.
I just made one for PayPal using my MacBook which seems to have ended up in Bitwarden rather than the mac thing. But there's nothing in Bitwarden to say list all passkeys. Not sure how I check elsewhere. Maybe they should email you "you have created a paypal passkey in Tim's Bitwarden" or something. Then at least you could search the email for "passkey"?
I wonder if I can use Bitwarden on another device with that? I honestly don't know.
The only downside is unlike a house key, you can't get a backup "cut". Copying a physical passkey currently isn't possible. If you lose it, you've lost access to all your logins. As the article says, their recommended workaround is to keep backup physical passkeys, and log all your passkeys (including the backups) into every site. Which is insane - very few people have the patience to do that.
The article is really a long rant about that one issue - there is currently no way to securely backup a physical passkey. Solve that, and all the other issues melt away.
I for sure don't. Websites only know there is a passkey associated with my account, and the OS only knows there might be one on the device, or maybe on another device, and offers me options to check here or do a Bluetooth/QR Code dance, and when all of them fail, I'm no closer to knowing where the damn passkey is.