Hacker News new | ask | show | jobs
by skibbityboop 586 days ago
Yeah, if your device is lost or destroyed and you rely on passkeys, you are well and truly f**ed. Your only hope is if you have recovery passwords stored in a password safe or manager. If you already have that safe or manager, than you can already very easily have 25+ character passphrases for every site you use, so what have passkeys gained you except having to be double-vigilant about having a recovery method for every login you create?
1 comments

That’s not true. You can use iCloud keychain and have numerous recovery options, including other passkeys. A lost device is not a critical issue at all.

To your questions, the password safe can store passkeys as well. The entire point is to get to a place where we aren’t all dependent on some remote site’s security to keep our secrets safe. Why use a 25+ character password which can be compromised in a number of ways when a passkey doesn’t involve sending secrets at all?