• Natanael@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    8 days ago

    That’s literally no different from a regular password manager or having a 2FA TOTP code app set up for it

    • mspencer712@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      8 days ago

      Are you sure? TOTP secrets can be exported. I think passkey implementations explicitly prevent that. Unless I’m missing an option to export passkey creds, e.g. print them out.

      That same disaster recovery feature (which I need) also helps avoid a future where every forum and avenue of dissent requires dis-repudiation via passkeys. It’s a weird nuance, ascribing a social effect to a simple ability to back up your keys without backing up your whole phone.