Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

  • kjetil@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    3 hours ago

    Dont they all sync to the respective cloud services?
    iOS vault -> synced apple cloud Android vault -> synced with Google cloud?
    Windows Hello -> synced with Microsoft account?

    And if they’re not synced, that’s even worse. Loose your device and loose your account. Or keep track of which of your 5 devices are have keys for which of your 150 accounts

    • Passerby6497@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 hours ago

      Well shit, you’re right. I must not have been paying attention when they updated them to include that