this post was submitted on 11 Nov 2025
290 points (87.6% liked)
Technology
76799 readers
3039 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Say you don't understand passkeys without saying you don't understand them...
A passkey uses public key cryptography to secure your account instead of a password, it only grants you access to the one account you set it up for, and the account provider only holds your public key, you control the private key. Your passkey is a secure alternative to passwords because you CANNOT reuse it across services, cannot reasonably remember it, and the method of using it isn't by copying and pasting into a field like a password, so it isn't susceptible to the same attacks.
If the provider loses your public key, they can't give you a challenge to verify you have the private key, so you lose access. Just like if they lose your password hash. It's an identical scenario.
Everything you said is correct, but you misunderstood my point. I was referring to the fact that Google/Apple/whatever would hold your private key. In practical terms, it is barely different from the existing "Sign in with Google/Apple/whatever".
The assumption is that the native passkey manager on the device (iPhone, android, windows) would sync the passkeys (to Apple , Google, Microsoft) for protection against device failure and easy of use across devices. Or you risk loosing your accounts if you loose your device.
That would happen if you store your passwords there too...
If you're proactive enough with your passwords to manually store them in your own vault, you can be proactive enough to not use the corporate vaults that don't allow exporting. This isn't a "downside" of passkeys, it's a downside of using the built in managers.