Remix.run Logo
nottorp 3 hours ago

> When you have to handle a colleague’s computer, it gets much more inconvenient.

Let's add to that: What if you're on holiday and your phone gets stolen or is suddenly 20 meters under water because it fell off the boat?

What if you are a normal person who only has a phone and it simply dies for one reason or another?

You get a new phone then hire the boat again, go above where your phone fell in and hope it syncs your passkeys?

AntonyGarand 3 hours ago | parent [-]

You should always plan for your currently active device to be bricked suddenly and act accordingly.

You either should treat your passkeys with a backup like any data, this can mean multiple hardware keys or a cloud backup of your passkey, like bitwarden or the provider's native backups.

raesene9 2 hours ago | parent | next [-]

The key word in the post you're replying to is "normal". Non-technical people don't (in my experience) plan for this kind of thing, like at all.

The idea of multiple hardware keys, which have to be enrolled individually to every site, is just not an ordinary end-user friendly activity.

So passkeys may be great for technical users (who are happy doing that) or corporate users (where centralized IT systems can be put in place) but not for standard non-corp users (which realistically, is most people)

2 hours ago | parent [-]
[deleted]
nottorp 2 hours ago | parent | prev [-]

Bet you have a home lab.

Not talking about you. After all passkeys are not there to protect people who have home labs and don't recycle passwords anyway? They're for normal people who only have one device.

> who are happy doing that

You think they're happy? I'd say they grudgingly comply at best.

Suppose you do want a secure solution for the main sites your stuff is on. But every piece of shit content mill also wants to set up a passkey.

Edit: wow i missed this:

> a cloud backup of your passkey

... which is protected with what, a passkey?