Remix.run Logo
AlexandrB 2 days ago

My elderly mother accidentally created a passkey (in Chrome) for one of her accounts. Normally, I try to keep a copy of her accounts and passwords in case she forgets them so I can help her out. With the passkey, this is impossible.

She doesn't know how she created one, she doesn't know what it is, and I don't know how to explain to her that if her PC dies I won't be able to help her log back into her account. I'm not even sure how I'm going to migrate this thing to a new PC for her.

MBCook 2 days ago | parent [-]

Any decent password manager can handle all of those. Apple does. I’d expect the same of Chrome, Edge, Firefox and 1Password but don’t personally use any of them.

Why not just set yourself up to be able to access her password vault? Why is copying magic strings a better solution? You could have done that to get password access without passkeys existing. So they change nothing.

ivlad 2 days ago | parent [-]

If you are going to store passkeys in a password manager, the whole situation is no more secure than just using passwords.

Consider:

1. Password managers tie passwords to sites, so phishing-resistance is achieved. 2. Password managers allow long, complicated, individual password per web site, so compromise blast radius is 1.