WebAuthN is great, but I can't help but feel that Passkeys are actually a step backwards. At least on iOS, there is no way of preventing them from being synced to iCloud, which is the opposite of what I want for high-stakes credentials like bank accounts or government e-signatures. I've tried to raise [1] a related issue (i.e. the inability for relying parties to opt out of credential syncing, if not an explicit requ…
If Google/Amazon/Apple/Meta/whoever locks your account out, you now lose access everywhere.
This isn’t a theoretical risk. You’ll see lots of people complain about this online.
Also, Passkey providers now get sweet sweet metadata about your accounts around the web.
But yeah, authn is hard to do right. Equally, asking your users to fall into $BIG_PROVIDER’s arms seems wrong.
My personal hope is that various accountable nonprofits will begin to offer passkeys.