Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
That’s not how it is and not how they were designed. It was assumed from the beginning that they would live in “an ecosystem”, ie tied to secure storage and secure distribution by some system handled user side and indeed that is what phase 1 looked like: Google, Microsoft and Apple stored them on your device and replicated them across your devices. Phase 2 introduced a “interception” API so other providers could get involved easily - so providers like 1Password could rely less on browser hacks and also offer secure storage and secure distribution. Then finally, phase 3, now more or less locked down, described a portability system so that you can migrate to other ecosystems.
That’s not how it is and not how they were designed. It was assumed from the beginning that they would live in “an ecosystem”, ie tied to secure storage and secure distribution by some system handled user side and indeed that is what phase 1 looked like: Google, Microsoft and Apple stored them on your device and replicated them across your devices. Phase 2 introduced a “interception” API so other providers could get involved easily - so providers like 1Password could rely less on browser hacks and also offer secure storage and secure distribution. Then finally, phase 3, now more or less locked down, described a portability system so that you can migrate to other ecosystems.