Hacker News new | ask | show | jobs
by growse 782 days ago
> I somehow can't just wrap my head about that they are.

Passkeys are just resident webauthn credentials. Nothing more complicated than that.

> and that's why you have to use a proprietary device with custom hardware from a random company to act as a middleware between your actual secrets (hidden in-device) and you, and trust that device and company to handle the auth for you.

There's a few open source password managers that support passkeys now.

1 comments

> Passkeys are just resident webauthn credentials. Nothing more complicated than that.

THIS is the explanation that I was looking for. Short and straight to the point.

Thanks!