upvote
I've taken up the strategy of telling any less-technical person who asks me about passkeys that they are the mark of the beast, intrinsically evil, and should be avoided at all costs, and I encourage all y'all to do the same.

Maybe, at some distant point in the past, there was a plan for a whole system of intercommunicating implementations of passkeys. That is no longer the case. The moment that they decided to include the information necessary to only allow the use of certain passkey vaults in the protocol, and then use that capability to threaten to lock out certain vaults that dared to let users actually be in control of THEIR OWN DAMN CREDENTIALS, it invalidated the entire project in my eyes. Passkeys cannot be trusted, they are designed to let entrenched powers hold your authentication hostage, and should under no circumstances be allowed to take root in the computing ecosystem.

reply
>...they are the mark of the beast, intrinsically evil, and should be avoided at all costs

That's basically my recommendations to people.

1. Avoid using them if possible.

2. If you have to use them, make sure you have a password login to fall back on.

3. If the site forces you to use them, make sure you don't use it for any thing you rely on.

reply