logoalt Hacker News

dfabulichtoday at 3:23 PM1 replyview on HN

Passkeys aren't tied to physical hardware. They're tied to your password manager. Passkeys are just passwords that require a password manager.

On Windows, macOS, iOS, and Android, there's a cloud-based password manager built into the operating system, so you can use your passkey anywhere you use that password manager.

Microsoft, Apple, Google, 1Password, and Bitwarden all have password-manager apps for Windows, macOS, iOS, and Android.

Pick a password manager and use the same one everywhere, and your passkeys will be available wherever you go.


Replies

xg15today at 4:19 PM

Well, unless you have a device-bound or FIDO2 key, according to the post.

And I think for FIDO2 keys, this is fine. If I can register a key (plus a backup) the usage doesn't seem so different from a regular key.

For the rest, I think what irks me is the feeling of "you have free choice which corporation you want to entrust all your login credentials with, but you will have to choose one". Previously, password managers were a convenience (that incidentally also increased security, because they made keeping a separate, hard password for each domain practically feasible) - but nothing stopped me from keeping passwords at several different places at once or memorizing some of them, in case I lose access to the password manager.

Now suddenly, they become the arbiters of my logins everywhere. What happens if they ban me, or go out of business or get bought up? (Or in Apple or Google's case, make arbitrary business decisions that can now affect the way I login to completely unrelated services?)