> 1Password already has a demo available, and Bitwarden has said they're working on it.
It's a step in the right direction, but I worry that:
A) 1Password seems to be treating the problem as solved just because you can use 1Password on multiple devices. They haven't talked about migrating from 1Password to Bitwarden and back again.
B) As far as I can tell, this seems to be not a part of the spec at all. Correct me if I'm wrong, but it seems like the FIDO alliance is hoping that portability becomes more of a thing, but they're not willing to say "there should be a standardized API for this". And I think that's a huge mistake, saying that every platform will individually build support for every other platform (and that we'll hope platforms will provide these mechanisms in the first place) is a recipe for killing off smaller 3rd-party clients, because they just won't be supported.
---
> You could get more specific and say the act of logging in with a passkey is phishing-proof, but access to the passkey "wallet" is not necessarily.
That's a really good way of phrasing it; I think I agree there. And yeah, 100% agreed that it's a step in the right direction, I love the core idea behind Passkey, I think it's a massive step forward for security that's hindered by concerns around portability, attestation as DRM, etc, etc...
I think what I'm getting at mostly when I point out that passkeys are not universally phishing proof is that the massive increase in security and phishing-resistance does not go away if there's generic support for migration between services that any 3rd-party platform can hook into. Yes, it's a phishing risk, but it's a phishing risk we've already accepted. Having FIDO mandate portability between ecosystems as part of the standard itself wouldn't get rid of the security benefits you describe.
And I do get people telling me "there can't be APIs for this in the standard because it defeats the entire point, they're no longer phishing-proof"; but I don't think that accurately captures the situation at all, because we already compromised on transfer between devices, they're already not completely phishing-proof. So there could be transfer methods defined by the spec that providers who wanted to say that they're compliant would have to offer, and those transfer methods could have the same security requirements around them that Apple uses when restoring keys to a new iPhone. It doesn't need to be platform-dependent, there could be an open standard around this and it wouldn't ruin the security of the passkeys to have that open standard.