3 ms·
Have we standardized a way to backup and export passkeys yet? Do websites commonly allow multiple passkeys to be registered?
by nixpulvis 2mo ago
Have we standardized a way to backup and export passkeys yet? Do websites commonly allow multiple passkeys to be registered?
- ecesena 2mo agoThere’s FIDO CXF/CXP: https://fidoalliance.org/specs/cx/cxf-v1.0-ps-errata-20260309.html https://fidoalliance.org/specs/cx/cxf-v1.0-ps-errata-2026030... To my understanding both Apple Passwords and the Android equivalent allow you to export passkeys to a different app (password manager), but I haven’t tried it yet. If anyone has direct experience I appreciate to know how it was.
- Gigachad 2mo agoI had a click around Apple Passwords on macos and I could not find a way to move my passkeys to another app. I could only see a way to share them with other Apple Passwords users.
- antgiant 2mo agoI can confirm it works on iOS 27. I haven’t tried elsewhere though
- MBCook 2mo agoI think it’s a 27 feature.
- Terr_ 2mo agoThose are the right questions: While I'd personally prefer full copy/import/export control, having the ability to set up an second key in advance is functionally-similar to having a backup of the first one. If I had my 'druthers: 1. All sites/services would allow the registration of 5 or more keys, which can be tracked/revoked separately. That way if one device is stolen, you can invalidate that key without affecting others. 2. There are two sets of keys: "Regular Use" and "Backup/Recovery". 3. Attempting to use a Backup/Recovery key prompts to user to confirm that they want to invalidate the Regular keys and promote the backup key(s) to the new regular. In this way, a compromised backup cannot be used in secret.
- nixpulvis 2mo agoIt's not functionally equivalent, but it is a workaround, but requires doing it on every site (if they allow it) and it cannot be freely moved and re-backed up offline from the site. The actual reason is people have many devices. I assume this is at least somewhat common, but I still avoid passkeys so IDK. You're designing a system where we should just be able to backup our own keys if we want to.
- BoppreH 2mo agoAlso, can I add a backup key without having the private key with me? Ideally I would like to keep a master key in a vault, to recover compromised accounts and such, but requiring me to load the master key to create every account prevents truly secure storage.
- j16sdiz 2mo agoFrom account security POV, it is better to disallow backup or export passkeys. Each device should get their unique key. This would be quite bad from usability or privacy pov, I guess.
- nixpulvis 2mo agoIt's ao comically bad it proves the while thing is a joke unless you're trusting Apple or Google to sync and back them up for you. One cynical angle at why the backup is being slow-rolled is because the major players have an incentive to not do it. They want you dependent on them and locked into their ecosystem. It's completely insane to treat a credential to an account as something that cannot be backed up. It implies there's another form of recovery, which likely means that key is only as secure as the other recovery options. And when it comes all the way back to the master key to your manager itself the loop falls somewhat apart. It's a hard problem, but passkeys aren't ready for me yet.
- jesseendahl 2mo ago>They want you dependent on them and locked into their ecosystem. This is a strange conclusion to come to when clearly a lot of effort was put into developing an open standard (Credential Exchange Format) to make it easy and secure to move credentials between vendors/ecosystems, without opening end-users up to phishing attacks on credential export. If big tech wanted to lock people in, it seems like it would have been a lot easier to just... not create an open standard.
- nixpulvis 2mo agoBug tech isn't a single entity. But I strongly believe a different group would have finished this obvious gap by now.
- esseph 2mo ago> backup / export Last I heard this was a major point of contention between two groups, and last I checked, both had extremely valid concerns. > Multiple passkeys I commonly have two software and two hardware keys registered per site.
- nixpulvis 2mo agoHow is this easier than just using a password manager? Why not standardize the password input mechanism so they reliably update, etc. I feel like all of the security of passkeys could have been build in a compatible way with new standards and enhancements to existing password interactions.
- esseph 2mo ago> How is this easier than just using a password manager? Easy and Secure are often at odds. I am using a password manager, I have a passkey saved in it. Should that service go down or have some kind of software problem with that passkey, I have physical ones which also can work for offline services such as my OS logins.
- nixpulvis 2mo agoWhy is a password manager a "service" it should really just be a program and as many encrypted backups as you want. Maybe you pay for them to host those backups, but that's a choice you should be able to make.