| ▲ | jimbokun 2 days ago | |||||||||||||||||||||||||||||||
Seems like the flow should be: 1. All passwords stored in password manager. 2. Login with password manager when logging in for the first time on a device. 3. Combination of OS and site/app notice that no passkey has been created for this account and offers to create one. This is presented to the user as “setting up the current device for password-less log ins.” 4. OS negotiates with site/app to install the passkey and use it for future log ins on the device. It’s presented to the user as a convenience clearly tied to this device. …but you still have your text password stored in the password manager’s servers… | ||||||||||||||||||||||||||||||||
| ▲ | akdev1l 2 days ago | parent [-] | |||||||||||||||||||||||||||||||
By still having the password the user can still be attacked via phishing | ||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||