3 ms·
So the same passkey is being used on multiple devices, rather than different devices (actually applications) having distinct passkeys. Doesn't that defeat one
by abdullahkhalids 1y ago
So the same passkey is being used on multiple devices, rather than different devices (actually applications) having distinct passkeys.
Doesn't that defeat one of the centrals aims of passkeys? In what ways is your setup different than random passwords in bitwarden - what's the additional security?
- greenicon 1y agoPasskeys cannot be phished. Other than that they shouldn't have a big advantage for a more professional user with unique, long, and random passwords. For the common user it should be a great upgrade, giving all these advantages with better UX.
- eviks 1y agoPassword autofill also provides that protection as it won't match on phishing domain
- ianburrell 1y agoAnother is that passkeys are single login and sites don’t use 2FA. Not having to get out TOTP or receive SMS is worth it. Basically, any site that does 2FA should take passkeys.
- eviks 1y agoYou can store 2fa in a password manager except for the dumb sms-bases ones, but that's still an extra step
- temp0826 1y agoThe password manager has become the device (and offers some assurance if the device is lost, as you can log into the manager on another device). I agree definitely isn't the original vision of passkeys (having a different passkey on every device, stored in separate password databases?), but it makes more sense for my cases.