4 ms·
Please, please, please stop using passkeys for encrypting user data
- deleted 7mo ago[deleted]
- apothegm 7mo agoNot to mention the challenges when (gasp!) a single user uses more than one device. Like, yes, some of us have both desktop computers and phones, thanks for asking. This is why I refuse to let most sites set me up with passkeys. I’m considering making exceptions for the ones that usually get this stuff right (like GitHub).
- timmyc123 7mo agoNot sure what you mean. In most cases, passkeys sync across your devices.
- throwaway798214 7mo agoPeople with all Apple devices do not consist "most" of users
- pabs3 7mo agoJust add more than one passkey to your account?
- apothegm 7mo agoOnly a small subset of sites seem to support that so far.
- code-e 7mo agoWhat's the difference between keeping a passkey in bitwarden, and just using a password, also in bitwarden?
- DANmode 7mo agoYour mom uses Bitwarden?
- zetanor 7mo agoMainly that a service can't refuse passwords from Bitwarden, whereas in a few years you'll find yourself reading an article about how a bank in Luseristan has decided to require that their users sign in using Passkeys stored in an attested authenticator (not Bitwarden) running on an attested device (not any current Linux desktop).
- markhahn 7mo agoMaybe I'm not getting it. Doesn't the problem start with ever deleting a passkey? That is: how do you ever know you don't need it anymore? Also, what is the alternative? Just a password that you store in the vault? Seems like deleting those gets you back to the same place (with all the disadvantage of a plain password).