Comment Insecure by design? (Score 2) 230
The basic idea of passkeys used to be that they are generated on-device and never leave the secure element. So there was no way that they can get stolen or subpoenaed.
Then Apple, Google and Microsoft decided it is too much hassle for users to create a different passkey on each of their devices and that they might lose access to a service if a device with a key on it gets destroyed or lost.
So they threw this basic feature over board and added cloud synced passkeys. No idea how they did that, because of the "never leave the secure element"-premise, but here we are. Somehow they did it anyway.
Does that mean that my passkeys can now be potentially stolen by a skilled attacker who can attack the cloud service of my hardware vendor? And that all my passkeys to all my services must be handed over after a court order? Am I missing something?