5 ms·
Passkey lock in appears to be a temporary issue. One of the WWDC announcements was that the FIDO alliance worked out a way to securely port passkeys between pla
by LexGray 1y ago
Passkey lock in appears to be a temporary issue. One of the WWDC announcements was that the FIDO alliance worked out a way to securely port passkeys between platforms. I expect Google to adopt import and export before year end.
I believe the issue Google is attempting to solve is frustration when a single web page spams multiple permissions requests. (Location, camera, microphone, advertiser tracking, notifications, privacy policy agreements, terms of service, etc…). The benefit to Google is better fingerprinting when a single sheet allows all at once.
Edit: perhaps they will sneak in a Google automatic login as a permission to smooth user interactions.
- josephcsible 1y agoIt's not temporary. The whole point of attestation in the passkey spec is to make lock-in permanent.
- skybrian 1y agoCould you explain more? For Apple, the web page I found seems to be an enterprise thing: https://support.apple.com/guide/deployment/passkey-attestation-declarative-configuration-depd218e61b5/web https://support.apple.com/guide/deployment/passkey-attestati...
- josephcsible 1y agoThat's the "cover story" use case. The real use case is so that passkeys created on Apple devices can only ever move to other Apple devices, and ditto for on Microsoft or Google devices, and the real point of attestation is so that they can force you to use theirs by cryptographically ensuring that you're not using open-source ones like KeePassXC.
- skybrian 1y agoBut the whole point of this new standard is to allow passkeys to be portable: https://arstechnica.com/security/2025/06/apple-previews-new-import-export-feature-to-make-passkeys-more-interoperable/ https://arstechnica.com/security/2025/06/apple-previews-new-...
- josephcsible 1y agoIf that ends up letting attested passkeys be exported outside of the Microsoft/Apple/Google oligopoly, I'll eat my hat.
- skybrian 1y agoWho uses attested passkeys? (Serious question.)
- AlotOfReading 1y agoAs an example, see this issue opened against keepassxc saying that if they continue allowing plaintext passkey export, they're at risk of being blocked once attestation is standardized: https://github.com/keepassxreboot/keepassxc/issues/10407 https://github.com/keepassxreboot/keepassxc/issues/10407 The goal here isn't maximizing user choice, it's to enforce minimum agreeable standards by the major vendors. It's up to you whether your personal needs wholly align with what they want to mandate, forever.
- skybrian 1y agoYeah, I’m okay with that. It’s also true that not just anyone can become a domain registry either, but we still have choices. It’s less convenient, but you can always create a new passkey manually for an account.