Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

you are viewing a single comment's thread
view the rest of the comments
[–] 34 points 10 months ago (1 child)

Password managers store passkeys. They’re portable and not device-locked. Been using them on Bitwarden for like 2 years now.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 10 months ago

    It is not portable in the sense that you need bitwarden installed on the device you are trying to connect from.

    Passwords can be plain text, which means I can copy, paste, and dictate them to a device that does not have additional software installed.

  • source
  • parent