7 ms·
This is a great point. And to respond to the other part of the parent comment about storing "all their credentials with one of the large tech companies" — you d
by QhwyF3AxE 3y ago
This is a great point. And to respond to the other part of the parent comment about storing "all their credentials with one of the large tech companies" — you don’t even need to do that, if you don’t want to.
Apple just extended their Credential Provider API such that passkeys can now be synced using external providers, meaning password manager apps can save and offer passkeys on iOS, iPadOS, and macOS. So you can choose to sync your passkeys with whatever your favorite password manager is.
See this page: https://developer.apple.com/passkeys/ https://developer.apple.com/passkeys/
And Google announced a similar API a month or two ago.
See the section titled "Passkey support for Android apps" on this page: https://developers.google.com/identity/passkeys/supported-environments#android-passkey-support https://developers.google.com/identity/passkeys/supported-en...
- rjzzleep 3y agoYou guys conveniently ignores the fact that Apple and Google are still the gatekeepers in that scenario.
- iknowstuff 3y agoHow so
- doublepg23 3y agoYes you need to trust your operating system developer to some extent. If your threat model includes not trusting the company that writes the source code to your OS…don’t use computers I guess?
- devsda 3y agoThe concern is not about trust but gatekeeping the providers. For example in the case of email, you generaly dont worry about google reading your email but we should definitely be concerned if gmail allows send & recieve from only few domains or providers it chooses.
- __MatrixMan__ 3y agoSuppose one does trust their OS developers. And they want to use some passkey-protected service. Does that service also have to trust the OS developers? Correct me if I'm wrong, but I'm under the impression that services can decide whose passkey implementations to trust. Seems like that should be up to the user, not the service.
- ptman 3y agoThe user picks the passkey, don't they? Android, Apple or Microsoft. Or Yubikey, or another token.
- shawnz 3y agoBut no more than they are the gatekeepers of your password when you use their keyboard software, right?