Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And what a surprise that is, the one feature necessary to ensure vendor lock in doesn't happen was at 0 priority before they rolled it out.


The whole point is vendor lock-in.


How does that work if you can register multiple different keys using different devices from different vendors on an account?

Edit: I took the last sentence out, it was childish on my part.


Can you, though? passkeys.io does not showcase this. The default assumption from every vendor is that you'll use their passkeys and they don't care about anything else. It's a very explicit silence, no "official" resource from any major vendor addresses cross-platform portability.

Yes, some individual implementers recognize the issue and have "log in with another device" (which is the best option you can have, although still quite clunky), so you can solve the chicken-and-egg problem of logging in on another platform's device to add your another platform's passkeys. But to best of my awareness, this is not a part of any standard or recommendation (it should've been).

And other implementers do the contrary and artificially limit your options so you can't add a portable authenticator with them without some hacking around.


What are the vendor options though? (I think) its Google, Apple, Microsoft, Yubico and 1password? None of which support exporting the keys as per other comments in this thread.

Also (i think) none of them are open source?


1password publishes their implementation: https://github.com/1Password/passkey-rs




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: