• Natanael@infosec.pub
      link
      fedilink
      arrow-up
      0
      ·
      8 days ago

      That’s literally no different from a regular password manager or having a 2FA TOTP code app set up for it

      • mspencer712@programming.dev
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        8 days ago

        Are you sure? TOTP secrets can be exported. I think passkey implementations explicitly prevent that. Unless I’m missing an option to export passkey creds, e.g. print them out.

        That same disaster recovery feature (which I need) also helps avoid a future where every forum and avenue of dissent requires dis-repudiation via passkeys. It’s a weird nuance, ascribing a social effect to a simple ability to back up your keys without backing up your whole phone.