logoalt Hacker News

tadfisherlast Wednesday at 11:09 PM1 replyview on HN

There is a project under way to specify how to "sync" device-bound keys between authenticators: https://fidoalliance.org/specs/cx/cxp-v1.0-wd-20241003.html

Ideally this should have been hashed out before deploying passkeys everywhere, but I guess you can always register multiple passkeys for the sites that allow you to.


Replies

nottorplast Thursday at 8:09 AM

Iirc the original idea was that passkeys should be device specific. Of course that's impractical so now they're morphing to a long password that a human can't process.

In a few years someone will post "how about a long human retainable passphrase?" as a new and improved discovery.

show 1 reply