4 ms·
This concern is valid depending on your threat model, but improvements are quickly coming to this area. Apple, Microsoft, and Google have announced that they wi
by sebk 4y ago
This concern is valid depending on your threat model, but improvements are quickly coming to this area. Apple, Microsoft, and Google have announced that they will allow syncing credentials between devices in their ecosystem (fully end-to-end encrypted, like a password manager), and several password managers have started to add software implementation of FIDO authenticators to their offerings. Hopefully in the near future we'll see the big vendors open up their APIs so that password managers can use the device hardware as well.
Of course, multi-device passkeys will not work for high assurance situations, as TFA calls out, but that's not likely the case for any of the services you currently use a password manager for anyway.
As it stands today, using passkeys with a software implementation, barring implementation bugs, is no less safe from credential loss than passwords in a password manager.
- b112 4y agoApple, Microsoft, and Google have announced that they will allow syncing credentials While your comment is fair, and I know you were just providing info, from where I sit, these are the sort of entities I never, ever involve in any form of private work, security, or communication.
- toomuchtodo 4y agoThis is a minority opinion though when compared to usage and market share of these orgs.
- mistrial9 4y agoas a US citizen, I absolutely do not accept these three giant companies running my access to financial services and governmental functions; just, no. Secondly, I will say that the entire surveillance-capitalism ideas of constant-on ID comes from a model of money lending that was built in the 1960s, ultimately by VISA and MasterCard. This worked well enough to generate the holders massive capital. no, no, no