logoalt Hacker News

akdev1lyesterday at 10:05 PM1 replyview on HN

> hence why passkeys were ideally device specific, non-exportable

Not true. The original concept was always for them to be cloud synced.

This has nothing to do with their anti-phishing capabilities. The anti-phishing capabilities come from the fact that the password manager authenticates the application before handing out the passkey. It doesn’t matter if they are synced across devices or not.

You are correct that other login methods might be weaker than passkeys. I’m not sure how that’s related to passkeys though. In real security sensitive applications the recovery process is “go to the bank’s branch and show them your driver’s license”.

> Your master password to your cloud PW manager's vault is also phishable

No, it’s not. You would need to steal my yubikey to get access.


Replies

ivladtoday at 2:46 AM

> Not true. The original concept was always for them to be cloud synced.

It was not. The original U2F spec was created before that idea was around and it talked about hardware security keys as means to store the primary key pair.