Remix.run Logo
preisschild 2 days ago

You can use both hardware bound passkeys (where you may not even be able to read the secret so you probably would want to add multiple device passkeys to a site)

or shared passkeys (where the private key can be synced through something like a cloud service across your devices, see Bitwarden, iCloud)

junaru 2 days ago | parent [-]

> hardware based

Sounds good until you realise theres no way to transfer/back them up and you are limited to 100 [1] (previously 25?).

Personally my password manager has almost 4x the entries so hardware passkey solutions are a joke leaving users with single option - upload their keychains to ms/apple/etc clouds where they can be requested by any gov under the sun for x reasons.

[1] https://support.yubico.com/s/article/How-many-accounts-can-I...

preisschild 2 days ago | parent [-]

That limit is only for a certain Yubikey model, not for all hardware-based fido2 authenticators.

> upload their keychains to ms/apple/etc clouds where they can be requested by any gov under the sun for x reasons.

If a HSM module (TPM, Apple/Android Secure Enclave) is used the private key is impossible to extract (and upload to a cloud) anyways

junaru 2 days ago | parent [-]

> That limit is only for a certain Yubikey model, not for all hardware-based fido2 authenticators.

Do you know who offers more? I deliberately chose Yubikey as example as their limit was the highest. Others like Nitrokey etc. support even less.

Telaneo 20 hours ago | parent [-]

Even if there are keys that offer more, the number 1 brand in hardware keys having that limit is not a good look if the idea is to transfer 'everything' to it.