6 ms·
Not really, the technology behind passkeys behave kind of like managed ssh keypairs. While they can be designed to have the secrets cloud synced (just lile how
by jabbany 3y ago
Not really, the technology behind passkeys behave kind of like managed ssh keypairs.
While they can be designed to have the secrets cloud synced (just lile how you can sync your ssh private keys), there's nothing preventing them from being implemented in other ways, like having them backed by a third party password manager or even a pyhsical token like a yubikey.
Of course, this depends on the software (OS, browsers) actually respecting and supporting that interoperability. But that's not really a limitation of the underlying tech.
- _delirium 3y agoIs there a way to store the ultimate root of trust somewhere non-digital? I currently have my most important root-of-trust passwords printed out on paper stored in places I consider long-term secure. At least in my personal physical and social context, I don't trust any cloud account or dongle to a similar extent.