←back to thread

225 points Terretta | 1 comments | | HN request time: 0.242s | source
Show context
taeric ◴[] No.41863484[source]
I'm super curious how this will ultimately work. As noted in another thread, secure enclaves aren't secure if they can be copied. Such that, if this is moving the passkey by copying it, I'm not at all clear on how that stays secure?
replies(4): >>41863618 #>>41866813 #>>41867580 #>>41894895 #
1. gcr ◴[] No.41894895[source]
Hardware-bound passkeys have always been copyable by the proprietary vendor.

Make a passkey on your Mac, it appears on your iPhone.

Make a passkey on your Android, it appears on your other Androids.

Anyone who can bind a new iPhone or Android to your Apple/Google account wins your passkeys. I think the only passkeys properly tied to hardware are dedicated FIDO devices.