Remix.run Logo
selicos 2 days ago

A password manager let's me use my service specific credential from any device, securely and decentralized.

Passkeys lock into a specific device and seem easy until you need to use another device.

But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems like a worse fix than existing tools for a problem that has better solutions.

eigenspace 2 days ago | parent | next [-]

Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.

preisschild 2 days ago | parent | next [-]

You can choose either if your password manager supporte Passkeys

eigenspace 2 days ago | parent [-]

Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.

VertanaNinjai 2 days ago | parent [-]

Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?

tzs 2 days ago | parent | next [-]

There's a protocol, FIDO Credential Exchange Protocol (CXP) which is currently at proposed standard status. It is supported by Apple and Google and some third party password managers (1Password, Bitwarden, and Dashlane). (1Password is kind of annoying though as its CXP export only supports exporting everything. There is no way as far as I can tell to export just a single item yet).

Once 1Password supports proper single export when I make a new passkey I'll store it there and later export it to Apple.

Meanwhile I simply make two passkeys. I've only run into I think two sites that supported passkeys but would not let me make two.

On most sites making a second passkey is as simply as going to your security settings, finding the passkey settings there, hitting the "add another passkey" link, and pointing your phone at the QR code it shows, and then on those phone choosing the password manager that you did not use for the first passkey.

timmyc123 2 days ago | parent | prev [-]

https://mobileidworld.com/apple-introduces-cross-platform-pa...

https://support.google.com/chrome/answer/13068232?hl=en&co=G...

https://1password.com/blog/import-autofill-organize-whats-ne...

xg15 2 days ago | parent | prev | next [-]

How do you move your passkey from Apple's keychain into the password manager?

juanpicardo 2 days ago | parent [-]

in the ios password app you can tap on the button to export data to other app. it will show you the list of installed apps that can import them. works with passwords and passkeys.

I moved all of them from my iphone to a selfhosted bitwarden in two minutes.

xg15 2 days ago | parent [-]

Ok, good to know that.

I'm surprised selfhosted services would be allowed in that list. Isn't there the "risk" that you can then extract the raw key from your selfhosted instance?

2 days ago | parent | prev [-]
[deleted]
voxic11 2 days ago | parent | prev | next [-]

I put my passkeys in my password manager and it works fine.

mpalmer 2 days ago | parent | prev | next [-]

    it's one password to everything
You are entirely mistaken. Passkeys involve a third party storing a public key on their infrastructure, while you hold the private half of the key, somewhere.

Passkeys are never reused. Even for the same person, they are always unique across websites, and across devices.

QGQBGdeZREunxLe 2 days ago | parent | prev | next [-]

1password and KeypassXC both support passkey syncing across devices and operating systems.

pibaker 2 days ago | parent [-]

Until service providers ban them for being insecure — "if you can send your passkey to any other device, you can also send it to a phisher."

QGQBGdeZREunxLe 2 days ago | parent [-]

Passkeys have preventive measures for phishing.

https://bitwarden.com/resources/passkeys-are-phishing-resist...

yandie 2 days ago | parent | prev | next [-]

I keep all my passkeys in 1 password. So magical

arianvanp 2 days ago | parent | prev [-]

You're arguing against a straw man.

All password managers support passkeys.

Both apple and google allow exporting your existing passkeys to third party password managers too.

Also each website gets it's own unique public key with passkeys. It isn't a single credential

You're literally arguing a strawman

a day ago | parent [-]
[deleted]