this post was submitted on 11 Nov 2025
281 points (87.9% liked)

Technology

76917 readers
3230 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 

Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

you are viewing a single comment's thread
view the rest of the comments
[–] HulkSmashBurgers@reddthat.com 56 points 1 week ago (8 children)

The eco-system lock-in makes this a non-starter for me. If I could store the private keys in something like a keepass vault (or that) and do the authentication magic from that I would consider it.

[–] cmhe@lemmy.world 17 points 1 week ago* (last edited 1 week ago) (5 children)

You can? At least I do that. I host vaultwarden myself and store the passkeys there.

Passkeys to me are just a better way to autofill in login data.

[–] barryamelton@lemmy.world 18 points 1 week ago (3 children)

OK, now think how nontechnical people will not be able to do it. They will be tied to Google/X-corp for all credentials, even government ones. Waiting to be banned if their social credit is too low.

[–] cmhe@lemmy.world 1 points 1 week ago

True. But I would say that this isn't an issue intrinsic with passkey. Many people don't have time/energy or the attitude to think critically about technology and are herded towards Google/X-corp/etc with offers of convenience and because they are often the only offered choice on the web sites. But from the POV of passkey they just act as a password manager.

load more comments (2 replies)
load more comments (3 replies)
load more comments (5 replies)