logoalt Hacker News

Groxxyesterday at 6:37 PM0 repliesview on HN

Device loss:

If you had multiple devices set up on the site (each site must have done this individually), you just use a different device.

If you had synced your passkeys somewhere (note that the spec allows sites to block this, though I'm not aware of any actually doing so), you sync them to the new thing and log in normally.

If you did none of those, it's gone forever. Do the account recovery process, if one exists.

So it degrades to equal or worse than passwords in all cases (which cannot block backups or syncing, and you can enter them individually by hand so you're not exposing all your passwords to the device, and you can communicate them over the phone or in writing), for device loss purposes.

Restoring access in this scenario is imo one of their worst qualities.