Hacker News new | ask | show | jobs
by cyberax 720 days ago
Yeah, Apple's gonna Apple.

In other words, they'll use Passkeys as a way to deepen the vendor lock-in. It has already started. For example, try to log into your Apple ID account using Safari, and it works via passkeys. No password needed. That's because Apple created a Passkey for apple.com automatically behind your back.

Now try the same from Firefox with BitWarden, and it doesn't work. And of course, there is no way for you to set up the passkey manually.

There's also no API to export it. Wouldn't it be nice if you could install BitWarden desktop client, and then use it migrate your passkeys? Nope. Not an option. The entitlement to interact with the Keychain for passkeys is only given out to browser vendors.

1 comments

Why would you need to "migrate" a passkey, you can just log in to wherever it is and create a new one instead of the old?
Because it's tiresome if you have hundreds of sites. You'll need to run password recovery flows on all of them.