6 hours ago · 7 min read1422 words · Tech · hide · 0 comments

Passkeys are finally mainstream and the specs for passkeys and WebAuthn Level 3 (the latest version) just reached Recommendation status at the W3C. Yet education on passkey's security properties, proper implementation, and how they work has not reached a ubiquitous threshold in the software development community. A question I recently answered in a chat started with:Seeing lots of passkey being pushed by various services. Is there a reasonable way to “own it”? Is it still very bad at a full loss recovery?Extension based passkeys generally have a way to export them. Whether it is in a format that can be imported to the same service or another is an active area of standardization and adoption.Check outFIDO Alliance's CXF Specifications pageCredential Exchange Format Proposed StandardCredential Exchange Format ErrataPlatform synced passkeys can be exported too — at least if you're on Apple Passwords or Google's Password Manager. Windows Hello is device bound and the Microsoft Password…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.