• sunbeam60@feddit.uk
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    3
    ·
    edit-2
    3 days ago

    Passkeys don’t require physical storage at all. All of my passkeys are in the cloud, synced across platforms.

    • Kangae_Hishiryo@scribe.disroot.org
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      3
      ·
      4 days ago

      No, Passkeys are generated on device against a public key on the server side. If you lose the device where you created your local, private key, then you lose access to everything. Also there’s FIDO (and implementations as YubiKey and NitroKey).

      • tea@lemmy.today
        link
        fedilink
        English
        arrow-up
        13
        ·
        edit-2
        4 days ago

        This is a good encapsulation of why passkeys are having a hard time. There are so many different ways to interact and it’s confusing for the user. There are physical FIDO keys, there are keys you create per device, then there are passkeys that the “device” is a password manager like bitwarden which is cloud based and follows you from wherever. It feels like they offer very different levels of security but do not look very different to the passkey issuer.

        • Kangae_Hishiryo@scribe.disroot.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 days ago

          Yeah, also cloud providers can easily lock-in yourself, and self host is a pain in the ass and availability with that method is a problem, especially if where you live there are problems with the power supply (even if you use battery equipment it can be a problem if you go many hours without electric service).

      • sunbeam60@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        3 days ago

        That’s not how it is and not how they were designed. It was assumed from the beginning that they would live in “an ecosystem”, ie tied to secure storage and secure distribution by some system handled user side and indeed that is what phase 1 looked like: Google, Microsoft and Apple stored them on your device and replicated them across your devices. Phase 2 introduced a “interception” API so other providers could get involved easily - so providers like 1Password could rely less on browser hacks and also offer secure storage and secure distribution. Then finally, phase 3, now more or less locked down, described a portability system so that you can migrate to other ecosystems.