logoalt Hacker News

preisschildtoday at 6:25 PM1 replyview on HN

You can use both hardware bound passkeys (where you may not even be able to read the secret so you probably would want to add multiple device passkeys to a site)

or shared passkeys (where the private key can be synced through something like a cloud service across your devices, see Bitwarden, iCloud)


Replies

junarutoday at 7:29 PM

> hardware based

Sounds good until you realise theres no way to transfer/back them up and you are limited to 100 [1] (previously 25?).

Personally my password manager has almost 4x the entries so hardware passkey solutions are a joke leaving users with single option - upload their keychains to ms/apple/etc clouds where they can be requested by any gov under the sun for x reasons.

[1] https://support.yubico.com/s/article/How-many-accounts-can-I...