Remix.run Logo
eviks 3 hours ago

> Since they are bound to the site they are created for, they cannot be phished by a hacker’s fake login screen.

With the app you use to store those keys (a password/key manager) it's the same - you simply wouldn't have an autofill working. Sure, people can and will circumvent this for the benefits of the scammers, just like they can circumvent passkeys using non-passkey login option, indeed:

> weakest recovery method: SMS

> If a site suffers a data breach, passkeys are asymmetric and cannot be recovered from the server-side details.

Similarly, don't other modern password storage methods have the same property?

> lacks the decades of UX polish towards password autofill.

A lot of years in those "decades" have been wasted polish-wise: you still can't log in with a single button, e.g., many popular sites only fill a username first, then require an extra dealy and action before accepting a password