• Natanael@infosec.pub
        link
        fedilink
        arrow-up
        0
        ·
        8 days ago

        That’s literally no different from a regular password manager or having a 2FA TOTP code app set up for it

        • mspencer712@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          8 days ago

          Are you sure? TOTP secrets can be exported. I think passkey implementations explicitly prevent that. Unless I’m missing an option to export passkey creds, e.g. print them out.

          That same disaster recovery feature (which I need) also helps avoid a future where every forum and avenue of dissent requires dis-repudiation via passkeys. It’s a weird nuance, ascribing a social effect to a simple ability to back up your keys without backing up your whole phone.