4 ms·
Shameless plug to my own passkey manager, which is 100% open source: https://bulwark.id https://bulwark.id One of the big challenges to passkeys right now is t
by cmdli 4y ago
Shameless plug to my own passkey manager, which is 100% open source: https://bulwark.id https://bulwark.id
One of the big challenges to passkeys right now is that they aren’t as versatile as passwords, but this doesn’t have to be the case. Passkeys should be able to be exported and stored anywhere you want (ideally in an open source solution). Bulwark Passkey supports that right now, but I’m glad that other products are also providing solutions to users for the same problem.
- wkat4242 4y agoThe problem is that big companies don't want them to be as versatile. They don't trust us to manage our credentials. Hence FIDO2 and Passkeys feature 'attestation' that allows them to only accept 'trusted' implementations. This accreditation is a crypto process so it can't be faked. So, you can't just put your keys in any app you wish, like you can with TOTP. There will be strong pressure to just 'go with the flow' eg mainstream OS implementations and us with niche OS or cross platform requirements will be ever more marginalized. Any complaints will be simply rebuked with "For security reasons" or "We only certify implementation X, Y and Z". My work is already doing this, they only support Yubikey and one other brand through their Identity Provider, if you have one of the open source tokens you're straight out of luck. Passkeys don't work yet either but I'm sure they will only 'certify' Apple and Microsoft and leave the rest hanging. They love quoting the pareto principle / 80/20 rule as an excuse.
- CMCDragonkai 4y agoThis sounds like an antitrust issue. Similar to Microsoft windows and the explorer browser.