5 ms·
I'm pretty sure passkeys are just a rebranded version of virtual WebauthN tokens. So while passkey secrets can be synced (unlike U2F physical tokens) they can
by jabbany 3y ago
I'm pretty sure passkeys are just a rebranded version of virtual WebauthN tokens.
So while passkey secrets can be synced (unlike U2F physical tokens) they can also be implemented as being backed by a physical token (think Yubikey) that never goes om the cloud.
- d0mine 3y agoThere is theory and there is practice. What grandparent comment says is the likely outcome in practice
- mynameisvlad 3y ago... Unless you care about that and use a Yubikey or other physical security key. There is absolutely nothing stopping you from doing so as long as your Yubikey supports WebAuthN (the latest do). You are prompted to use another phone or physical security key if a resident key isn't found on your device, and even if it is, you are given the option of doing so instead of using the one found. This is not a hypothetical feature or theory or something, it's part of the spec and is implemented. It's as practical as it gets.
- hooverd 3y agoUnless the website decides to enforce attestation and not allow that.