Hacker News new | ask | show | jobs
by upon_drumhead 720 days ago
This is exactly why I'm not using passkeys. I even trust Apple's statements that they can't view the key material, however, if Apple ever decides my account is no longer in good standing, I still want to access all my other accounts and as it stands now, you'd lose access to everything.
1 comments

Passkeys are stored in Keychain which is stored locally and synced (unlike Sign In with Apple which requires an active Apple ID)
That helps a little, but it's still a big problem. In particular, consider the situation in which Apple deems you persona non grata, and then your iDevice starts getting old and unreliable. As soon as it dies, you'll be locked out of everything forever since you can't move your passkeys to a new device without Apple's blessing.
You do know that you can swap a passkey for another using a new provider?

It's not like if you create a passkey on a Google device, you're forever bound to Google.

Many sites stupidly only allow you one passkey or FIDO U2F key.
Isn't that like saying that password managers don't need to support exporting, since websites support changing your passwords?