2 ms·
My biggest gripe with passkeys is that the spec seems to force non-interoperability. I use a password manager and I would have no issue storing a private key in
by steve_avery 10d ago
My biggest gripe with passkeys is that the spec seems to force non-interoperability. I use a password manager and I would have no issue storing a private key in a profile there, but I am literally not allowed to be able to copy the private key. If a spec thinks it knows better than me, I won't use it.
And don't you just love the fact that now Apple and Google and Microsoft have MORE control of my identities across the web?
- teravor 10d agosome password managers can pretend to be a passkey. but I don't use them because it requires finicky brittle configuration (and docs lookup whenever you want to redo it). if passkeys had a simple text challenge response text option it would be fine, you would basically be using something like PGP logins. and would be easy to implement in a password manager interface. as a result, I have zero interest in passkeys. a pity as it could have been useful (cold storage password manger + physical passkey). you can never trust any service to honor "backup" login options, got burned once for "suspicious activity". that is, if you lose a login option (passkey is lost) they can demand it in the future to "verify".