Remix.run Logo
Liftyee 3 hours ago

YES. This exactly. I work across multiple devices, some of which are nonstandard/uncommon (Linux, Xiaomi China ROM, ...) and I've NEVER had passkeys work properly - yet everything constantly prompts me to add one. Even if they did work, I'd have to carry around hardware keys or register each computer separately. And the lack of backups if a device is lost/broken is definitely a larger concern for me than being phished of my TOTP keys.

girvo 3 hours ago | parent | next [-]

My wife clicked through a Google dialog and suddenly was using a passkey. It absolutely happens, though IMO more to the non technical users. I know what those login dialogs and pop ups mean, and decline them.

(At least til I get around to setting up my new usb c yubikeys!)

utopiah 2 hours ago | parent | prev [-]

> lack of backups if a device is lost/broken

Same as traditional physical keys, you don't have a single key, you have multiple ones precisely so that if you lose/break one, you are not stuck and can go to the local locksmith and get another one in minutes.

In fact it's even nicer since you can just re-use the backup key with no security loss by revoking the other one, and buying another key.

cesarb 41 minutes ago | parent | next [-]

> Same as traditional physical keys, you don't have a single key, you have multiple ones [...]

I have multiple identical ones.

> [...] and can go to the local locksmith and get another one in minutes.

Can I go to the digital equivalent of a locksmith (like a backup software) and duplicate my passkey? Can I do that with only my passkey in hand (without having to do anything to the corresponding lock, or having to contact its issuer), like I recently did with a physical key?

account42 an hour ago | parent | prev | next [-]

For physical keys I don't need to ask permission to be able to make a second or third copy.

utopiah an hour ago | parent [-]

You don't need to ask permission to buy another key then register it to your self-hosted service.

In fact if you have the technical skills to make your own physical key and respect standards, e.g U2F, you don't even need to buy one and it will work with existing devices and services. I can recommend the Precursor for an interesting exploration of that from a verifiable software/hardware perspective.

cpburns2009 an hour ago | parent | prev [-]

It's not like physical keys at all. You can get copies made of those. Passkeys deliberately are not copyable.