3 ms·
Generally, the idea is that the private keys are stored on a TPM chip so they cannot be exported for security reasons, similar to a YubiKey or a crypto wallet.
by cmdli 3y ago
Generally, the idea is that the private keys are stored on a TPM chip so they cannot be exported for security reasons, similar to a YubiKey or a crypto wallet. I know Apple and Google are looking into trying to allow users to somehow export these keys elsewhere, but I'm uncertain how easy that will be or what tradeoffs there will be. I'm skeptical that Apple and Google will try to make it too easy since they benefit from user lock-in, but I would be happy to be proven wrong.
- lukeschlather 3y agoAs far as I can tell both Google and Apple have a mechanism to export the key so you can replicate the same key to another device. I run into this same situation with "HSM clusters" sold in enterprises where I don't really understand how people can claim with a straight face that you can't export the key to another device when they just explained to me that they export the key to another device.
- dvzk 3y agoThat is not Apple’s stated design at all. If you read Apple’s passkeys security document, it claims that the private keys are synchronized with iCloud and are recoverable following the loss of all devices. Non-exportable passkeys using the TPM is an HN myth.
- dwaite 3y ago> I'm skeptical that Apple and Google will try to make it too easy since they benefit from user lock-in, but I would be happy to be proven wrong. https://hachyderm.io/@rmondello/110329118270492669 https://hachyderm.io/@rmondello/110329118270492669 Apple's existing password manager (which is what surfaces passkey management) lets you export and import the database as a CSV file, same as Google and many others. I suspect the biggest missing piece is an agreement on an interoperable format - likely one that would also be interoperable for password and TOTP exchange as well.