Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

    • JackbyDev@programming.dev
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      2
      ·
      1 day ago

      Every time I was prompted to use one by plugging my phone in to my computer nothing happened. That was a little over a year ago.

      • Frezik@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        21 hours ago

        It’s been a very seamless experience with Bitwarden. Pretty much “click passkey, now logged in”.

        • JackbyDev@programming.dev
          link
          fedilink
          English
          arrow-up
          4
          arrow-down
          1
          ·
          21 hours ago

          I mean when I was trying to set one up. I wasn’t ever prompted to use a password manager. It just said to plug my phone into my computer. I did. And it didn’t detect anything. With user experience in setup that poor I don’t trust them yet.

          • sonofearth@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            edit-2
            12 hours ago

            What are using lol? I have never been asked to plug in my phone to a computer. I have use Bitwarden and KeepassXC and also used my phone to scan the QR in chromium browsers for passkeys and it just worked in all the browsers flawlessly (even ungoogled chromium). I just want Linux Distros to allow setup a default password manager for the user and implement passkeys auth mechanism for the apps installed in the device.

            • JackbyDev@programming.dev
              link
              fedilink
              English
              arrow-up
              1
              ·
              3 hours ago

              I don’t know what to tell you. Multiple sites and services asked if I wanted to set up a passkey, every time I got prompted to plug my phone in via USB, and nothing happened when I did. At no point in the process did it give me a QR code or ask me if I wanted to set one up through a password manager instead of a phone. I didn’t do anything special or incorrect. I followed the normal prompts they gave me.