upvote
A password manager let's me use my service specific credential from any device, securely and decentralized.

Passkeys lock into a specific device and seem easy until you need to use another device.

But instead of being a credential you own and control, across what could even be a local password manager, it's one password to everything. Maybe it is more secure than a regular password in some cases but it largely seems like a worse fix than existing tools for a problem that has better solutions.

reply
Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.
reply
You can choose either if your password manager supporte Passkeys
reply
Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.
reply
Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?
reply
1password and KeypassXC both support passkey syncing across devices and operating systems.
reply
Until service providers ban them for being insecure — "if you can send your passkey to any other device, you can also send it to a phisher."
reply
I put my passkeys in my password manager and it works fine.
reply
I keep all my passkeys in 1 password. So magical
reply

    it's one password to everything
You are entirely mistaken. Passkeys involve a third party storing a public key on their infrastructure, while you hold the private half of the key, somewhere.

Passkeys are never reused. Even for the same person, they are always unique across websites, and across devices.

reply
I've found passkeys generally simple and easy to use on MacOS and Android.

On Windows, I hate them. They always push me towards using a PIN instead of my Yubikey or password.

reply
The moment my mom needs my help to login to something because she clicked the button but now it's expired / she got a new phone / raison du jur, I will be totally unable to assist her. It's a horrible concept being foisted on unsuspecting victims.
reply
> Passkeys are phenomenal for a lot of consumers.

It already falls apart for regular interactions like "Can you send me the Netflix password?"

reply
> I can easily sign in to Amazon on my mac or iphone with zero friction.

And Windows, you need Bluetooth enabled on both devices, on Linux you need Chrome (and presumably bluetooth enabled). It makes you scan a QR code.

reply
>"Consider a user in the Apple ecosystem"

Already you're off-base. Of course it works when your devices are homogenized, but very little folks work that way. Some people have a Windows computer using Brave, an iPhone using Safari, an Android device using Chrome, and a work computer with its own hardware/software limitations and partitions.

Of course it works when your ecosystems are not diversified. Problem is, most people are.

reply
I refuse to be part of an "ecosystem".
reply
KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that).

No need to be a part of an 'ecosystem' to use a password manager or passkeys.

reply
Too late, you're using web standards, you're part of an ecosystem.
reply