Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
This is a good encapsulation of why passkeys are having a hard time. There are so many different ways to interact and it’s confusing for the user. There are physical FIDO keys, there are keys you create per device, then there are passkeys that the “device” is a password manager like bitwarden which is cloud based and follows you from wherever. It feels like they offer very different levels of security but do not look very different to the passkey issuer.
Yeah, also cloud providers can easily lock-in yourself, and self host is a pain in the ass and availability with that method is a problem, especially if where you live there are problems with the power supply (even if you use battery equipment it can be a problem if you go many hours without electric service).
This is a good encapsulation of why passkeys are having a hard time. There are so many different ways to interact and it’s confusing for the user. There are physical FIDO keys, there are keys you create per device, then there are passkeys that the “device” is a password manager like bitwarden which is cloud based and follows you from wherever. It feels like they offer very different levels of security but do not look very different to the passkey issuer.
Yeah, also cloud providers can easily lock-in yourself, and self host is a pain in the ass and availability with that method is a problem, especially if where you live there are problems with the power supply (even if you use battery equipment it can be a problem if you go many hours without electric service).