Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Every time Passkeys comes up, I think it's important to point out it takes the FIDO dongle model where a private key that never left the device, is now is passed into the hands of either Google or Apple for management.

I mean I totally understand how it could be easier to use and manage, but it just kind of scares me.



It's also important to point out that the key is E2E-encrypted using keys that never leave your device(s).

https://security.googleblog.com/2022/10/SecurityofPasskeysin...


I don't think it's quite right to say they never leave your device.

The page you linked says: "To address the common case of device loss or upgrade, a key feature enabled by passkeys is that the same private key can exist on multiple devices. This happens through platform-provided synchronization and backup."


It's nice that they explicitly addressed people who view Google as an attack vector.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: