Hacker News new | ask | show | jobs
by wolvoleo 6 days ago
Well that's why they can sync between devices. I don't really see the problem.

Even if you don't like to rely on big tech (google/apple), I don't either, there are many options now for full FOSS implementations like bitwarden and KeepassXC.

If you use a yubikey as a passkey then yes, that's not a great option also because most services don't allow you to enroll more than one passkey. But with bitwarden that doesn't matter.

3 comments

> Well that's why they can sync between devices. I don't really see the problem.

How do you sync passkeys to someone else's phone to authorize them to act in your name?

This is the basic use case, very common in the physical world, that security industry refuses to accept exists.

Passwords have this capability by nature.

> because most services don't allow you to enroll more than one passkey

Which is dumb and part of what makes passkeys not just useless, but dangerously so. Same story with 2FA, and the many services that only allow you to have one registered authenticator app at the time.

  > Well that's why they can sync between devices.
What Passkey implantation syncs between devices? I've only ever seen "cloud sync", e.g. syncing with someone else's computer. Can a user sync iPhone passkeys with her Boox E-ink tablet (Android)? Can either sync with a Debian desktop?
Yes you can do that with Bitwarden or KeepassXC.

Not sure if either works on iOS, I don't use that but they work on desktop and Android (you use KeepassDX there to read them).

Great, thanks.
KeepassXC now supports Passkeys? All right then, I accept that argument. I do use Keepass and compatible programs.
Yes! Though on Android you need the app KeePassDX to read them, I was mistaken about the name.