logoalt Hacker News

Gigachadtoday at 12:38 AM1 replyview on HN

>that synced passkeys should be secure in even in situations involving compromised clients?

I think that is the idea actually. By using secure hardware features it is in theory possible to secure the passkeys even in the case of compromised clients. Like how the iphone uses a security coprocessor to store the decryption keys and face id info out of the reach of iOS.

But this isn't overly concerning since it's still at a minimum as secure as passwords in a local compromise situation.


Replies

Briannajtoday at 2:09 AM

This is how I assumed it worked as well. I wasn't aware of the non User Verification method. I thought the passkey was tied to hardware. I thought that was the entire point. How wrong I was it seems.