4 ms·
Passkeys _may_ be synced, but that isn't guaranteed. For example a "device bound passkey" isn't synced.
by lsowen 9mo ago
Passkeys _may_ be synced, but that isn't guaranteed. For example a "device bound passkey" isn't synced.
- tadfisher 9mo agoThere is a project under way to specify how to "sync" device-bound keys between authenticators: https://fidoalliance.org/specs/cx/cxp-v1.0-wd-20241003.html https://fidoalliance.org/specs/cx/cxp-v1.0-wd-20241003.html Ideally this should have been hashed out before deploying passkeys everywhere, but I guess you can always register multiple passkeys for the sites that allow you to.
- nottorp 9mo agoIirc the original idea was that passkeys should be device specific. Of course that's impractical so now they're morphing to a long password that a human can't process. In a few years someone will post "how about a long human retainable passphrase?" as a new and improved discovery.
- SchemaLoad 9mo agoThey are still different to a password in that the service you are logging in to never gets the private key. So in the case the database gets compromised, if the service provider ensures no edits were made / restores a backup, there is no need to change your passkey since it was never exposed.
- yencabulator 9mo agoThat was possible before passkeys. https://www.rfc-editor.org/rfc/rfc9807.html https://www.rfc-editor.org/rfc/rfc9807.html https://en.wikipedia.org/wiki/Password-authenticated_key_agreement https://en.wikipedia.org/wiki/Password-authenticated_key_agr...