←back to thread

225 points Terretta | 2 comments | | HN request time: 0.001s | source
Show context
karlkloss ◴[] No.41867156[source]
If they can be moved, they can be stolen. This'll boost acceptance, but also open a can of worms.
replies(3): >>41867234 #>>41867321 #>>41871670 #
reshlo ◴[] No.41867321[source]
Passkeys are terrifying, and I don’t understand why the companies pushing them are doing so. What are their motives? What do they gain from catastrophically increasing the risk that users completely lose access to our ability to conduct our lives?

If someone steals my phone today, I can still access most of my accounts, and can regain access quickly to the others.

Now let’s assume passkeys are ubiquitous and used to log in to every website.

If they can’t be exported, then your entire digital existence is at the mercy of whatever device or technology platform you use to store your passkeys. If you lose access to the platform, you also permanently lose access to every single account you’ve ever signed up for. For me, that would include losing access to my retirement savings, tax records, and the ability to communicate with many of my friends, to give a few examples.

My computer also doesn’t have Bluetooth, which means I can no longer log in to any websites on it even when I do have access to my passkeys.

replies(2): >>41867346 #>>41867814 #
Hypnosis6173 ◴[] No.41867346[source]
I mean, isn't the idea from them that you have 2 or more of them?

Shure not everybody does that and some sites don't really support that but thinking about this concept of having "physical key s" to your data makes a lot of sense to me.

Don't know how this change will affect my trust in the concept

replies(4): >>41867365 #>>41867397 #>>41875149 #>>41879634 #
1. reshlo ◴[] No.41867365[source]
> I mean, isn't the idea from them that you have 2 or more of them?

So now I need to buy an extra phone from a different manufacturer than the one I already own, or sign up for another paid service? I’m starting to see what their motive might be now.

Is it even a requirement of the passkey standard to allow the user to create more than one passkey for your website?

replies(1): >>41875718 #
2. fmajid ◴[] No.41875718[source]
It isn’t but really should be. Apple requires you to register a minimum of two U2F keys if you use that as 2FA for iCloud.