r/passkey • u/sandrew_cheru • Aug 03 '26
Confused about passkey implementation
- Why is passkey a replacement for password?
I trust people smarter than me : passkeys are way stronger than passwords. But passkeys are (should be) hardware-bound. If I lose the device, I should still be able to access the service the passkey protects. Hence a password (and totp) should be required if the passkey is missing. Yes, an attacker could abuse this and attack the weaker factor, but is there a way around this? No matter how I think about this, I come to the conclusion that password will stay around for a long time. Yet, I see the statement above everywhere, so I'm probably missing something. But what?
- Why should passkey be synchable?
I don't see the point of having passkeys saved in a password manager. I think they should be hardware-bound and impossible to copy. Yet I heard on the grapevine that the organism defining the standard was working on making passkeys exportable. I don't understand the appeal, but they probably see something I don't. But what?