• mspencer712@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    10 days ago

    Passkeys make plausible deniability more difficult. “This user name isn’t necessarily associated with my real world identity” permits some important good things.

        • Natanael@infosec.pub
          link
          fedilink
          arrow-up
          0
          ·
          8 days ago

          That’s literally no different from a regular password manager or having a 2FA TOTP code app set up for it

          • mspencer712@programming.dev
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            8 days ago

            Are you sure? TOTP secrets can be exported. I think passkey implementations explicitly prevent that. Unless I’m missing an option to export passkey creds, e.g. print them out.

            That same disaster recovery feature (which I need) also helps avoid a future where every forum and avenue of dissent requires dis-repudiation via passkeys. It’s a weird nuance, ascribing a social effect to a simple ability to back up your keys without backing up your whole phone.