Understanding Passkeys
michal.sapka.me
Understanding Passkeys
1–10 of 79 posts
Re: Understanding Passkeys
#2Passage by 1Password: Add passkey support to your app or website - https://news.ycombinator.com/item?id=35988348 - May 2023 (114 comments)
Re: Understanding Passkeys
#3Nit: Pass[0] is not a GNU project.
Re: Understanding Passkeys
#4> ...I’d much prefer GNU Pass to support it Nit: Pass[0] is not a GNU project. [0]: https://www.passwordstore.org/
Re: Understanding Passkeys
#5Recent and related: Passage by 1Password: Add passkey support to your app or website - https://news.ycombinator.com/item?id=35988348 - May 2023 (114 comments)
Passkeys: A Loss of User Control? - https://news.ycombinator.com/item?id=35854216 - May 2023 (175 comments)
Re: Understanding Passkeys
#6> ...I’d much prefer GNU Pass to support it Nit: Pass[0] is not a GNU project. [0]: https://www.passwordstore.org/
Re: Understanding Passkeys
#7Passwords should always be kept as a valid authentication method.
The OP brings up a point about not having access to the private key... I agree with that. If I don't have access to the private key (like I currently do with ssh) then it's dead in the water to me.
Re: Understanding Passkeys
#8Features like this seem like table-stakes to me:
Re: Understanding Passkeys
#9I think it's unfortunate that Apple and Google are the ones who are most visible in the passkey space because it gives people the idea that passkeys are a locked-down authentication mechanism when they aren't.
Re: Understanding Passkeys
#10Is there any company actually providing anything resembling emergency access for Passkeys? A critical feature of password vaults for me is the ability of my heirs to get access to my passwords when I am incapacitated or dead. I can't print out my passkeys and store them in a safe, nor does there appear to be any system for allowing someone access to my passkeys. Features like this seem like table-stakes to me: https:…
You also should be able to back up passkeys onto a flash drive and encrypt them with a strong password. I don't think there's a good tooling for this right now, though. On macOS you'll need to go to Keychain Access and manually export the keys.
(I store everything important in an encrypted container, with the 128-bit recovery code printed on paper and stored in a safe deposit box)