←back to thread

184 points Bogdanp | 1 comments | | HN request time: 0.27s | source
Show context
seany ◴[] No.45106027[source]
Exporting passkeys is the single required feature for me to start using them more. The "anti phishing" push has really gotten a little too crazy. It seems mostly related to our legal inability to push security responsibility onto consumers.
replies(4): >>45106104 #>>45106144 #>>45106767 #>>45108849 #
jazzyjackson ◴[] No.45106144[source]
Given that you don't strictly need to have one passkey per site, is this desire to move passkeys around a holdover from wanting to "export" your passwords? Because if you can export them, an exploit can too. I find passkeys rather more interesting when they cannot be exported from a HSM / key enclave / yubikey, but of course I need to be able to register multiple yubikeys per site, and a few of my accounts didn't allow for this so I ended up using my yubikey for TOTP since I can have the same seed on multiple devices.
replies(3): >>45106498 #>>45106736 #>>45107969 #
1. tuckerman ◴[] No.45106498[source]
Export is a good check against lock in. I just went through my password manager and I have 60 passkeys. It would be a huge pain if I have to switch to a different password manager and there isn't export/import.