Hacker News new | ask | show | jobs
by inigyou 7 days ago
Why?
2 comments

Passkeys cannot be stolen. Yes, don't say that what if someone steals my iPhone, PIN, and adds their fingerprint.

Let's say eBay asks user to login. With passkey. Press and hold fingerprint etc. login done. Even with laptop.

And average Joe doesn't want to maintain a keepassdatabse sync it. Yes, you can always use your own server etc but others have life.

how do I back it up and transfer it to a new device? This is relevant because an attacker can also do that.
Buy a new iPhone. Sign into it. Everything is now available.

That is the reason: for the average Joe not having exportable passkeys is good.

Average Joe doesn't have to do backup. It is all automatic.

So I just have to get the victim to sign into my iPhone?
Yes. If you are such a person then do it.
Hiding the underlying exchange of data from the user does not mean the data is unstealable
With your logic nothing is unstealable. Go and watch film inception.

The main point is the average Joe it works seamless. And average Joe won't have to remember things.

Yes, it does. Not everyone wants to maintain password database.

Because as I just outlined, passwords, even when stored in a password manager, can be misused. (Phished, set to something weak/guessable, reused on multiple sites, leaked in a database breach, etc.)

Password managers make it easier to avoid those pitfalls, but passkeys make it nearly impossible to fall into them.