| ▲ | doodlesdev 2 days ago | ||||||||||||||||||||||
> You don’t. You don’t store anything at all. Yes, you do. Whenever a website offers to create a passkey, it could end up in any of these: - Samsung's Password Manager (if using a Samsung phone) - Apple's Keychain (if using an iPhone) - Google Password Manager - Your operating system's keychain - A bespoke password manager (e.g., Bitwarden or LastPass) - Your hardware key Most users do not have a security key fob. Instead, the proposal being mostly pushed is the idea that users can store keys on their own smartphones, making use of the modern TPM and chip security. Most of the discussion here revolves around that idea: "What if I lose my phone? What if I switch phones?" and that's why the problems seem so obvious to you. I absolutely agree the best solution is to use hardware keys, but I'll admit it's cumbersome if I need them for hundreds of accounts (which I do have), having to register both for every website and praying that I never lose both at the same time in the case there's no viable recovery flow for some of the accounts. Also, most of these hardware keys are limited to 25 or 100 resident keys, which again makes them unable to substitute passwords. Observe the usage of the term resident keys: passkeys do rely on the private key being stored on the hardware key, as that allows discovery. | |||||||||||||||||||||||
| ▲ | ivlad 2 days ago | parent | next [-] | ||||||||||||||||||||||
I was talking about the non-resident FIDO keys. “Passkey” term is meaningless unfortunately because FIDO Alliance did not define it initially, it was a marketing term invented by Apple and then re-introduced (or shoved down the throat) by the FIDO alliance. In non-resident keys scenario you don’t store anything and from what I see there is no security downside of using non-resident keys. Loosing both (or multiple) security keys is like loosing all your car or home keys. Very inconvenient, agreed. Anyway, I think we can agree that FIDO authentication protocol implementation is a mess. Apple and Google made it messy because they wanted to lock down users to their platforms and then password managers followed. As a result, the current implementation is not more secure than “login with Apple” or “login with Google”. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | zdp7 a day ago | parent | prev [-] | ||||||||||||||||||||||
I have to think people aren't doing any research. Both Android and Apple sync your passkeys to your account. You can toss all your devices in a wood chipper, buy a replacement and still have access to all your passkeys. | |||||||||||||||||||||||
| |||||||||||||||||||||||