Comment Re:Passkeys are better for everyone (Score 1) 203
> First of all, passkeys don't need to just be "on your phone". They can be stored anywhere. Microsoft and Apple both have them built into the OS. So you have a passkey on your laptop, as well as your phone. You can also store them in a U2F key like a Yubikey.
Attestation is what fucks this concept up.
> To answer your question - if you lose one passkey, presumably, you can use your other one. Everyone should always have at least two passkeys for any one account, for exactly that reason.
Ideally it should be in a software vault that is easily portable and can be backed up, instead of being tied to a vendor/device.
Doable with keepassxc, but the major vendors decided to fuck every one via attestation.
> If you lose *ALL* of the passkeys for an account - then you presumably should be having to go through some kind of in-person security procedure.
This falls into the category of purely unworkable.
> This is why, ideally, the government should be the one issuing passkeys, not Microsoft and Google and Apple. So that if you lost them, a trustworthy authority that you can go to locally - like the DMV - can fix it and restore your access. But we unfortunately are not there yet.
This says you have a very dangerous level of trust and are very privileged to have never been harassed for being a minority, trans, or the like.