Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You could have used an open source client to manage your passkeys as you like, including backing them up in your own storage format. I wrote about it here: <https://www.smokingonabike.com/2025/01/04/passkey-marketing-...> I was quite excited about it... until I found out that the Passkey spec authors have warned that client that it may face server-side bans because it lets you manage your own private key how you want, and the spec authors think this is appropriate for servers to do. So I deleted all my Passkeys. Sigh.


Reading these comments, I'm happy to see that I'm not the only passkey skeptic.


You'll probably enjoy this article from one of the original creators of the Passkey ecosystem:

> Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then by locking all their credentials into your platform, and even better, credentials that can't be extracted or exported in any capacity.

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shatt...

Fingers crossed the Passkey user experience remains so bad no one accepts them & they just die on the vine.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: