upvote
> * and with device attestation, they could be banned at any moment by any website with no recourse.*

Isn't this true of any authentication method? It doesn't seem unique to Passkeys.

reply
Now that I think about it, you are right. But if they could ban my use of written passwords as easily as banning my use of a particular passkey device, why go through all the extra hoops to just be as vulnerable as before? This seems like a whole lot of extra work to do that gains me nothing.
reply
I don't think the goal of passkeys was ever about making it easier to back them up or protecting you from websites that could ban you. I think (correct me if I'm wrong) the goal was always to make it nigh impossible for attackers to phish your credentials.
reply
I think it is important to explain why I and others are so reluctant to this.

In security, you identify reasonable threats. You can't protect against all of them, and some may even be contradictory.

When I get a call on my phone that says "Potential Spam", I have never even once in my life decided to run over to my list of passwords and hand them over to the President of the Spanish National Lottery. Not even once.

But on many, many occasions I have dealt with a simple system that was replaced by a more complicated one and something in that Rube Goldberg machine broke down and deprived me of access to money, email, even a parking permit to my office.

Passkeys seem to protect against the former case that has never happened to me, while increasing the chances of the latter that has happened way too often.

reply
It should go without saying that, while you've never given your passwords over to the President of the Spanish National Lottery, there people who do get duped into doing exactly that all the time.
reply