• bloopernova@programming.dev
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    edit-2
    1 year ago

    If anyone here does start using passkeys, just please please please make sure you have backups. And test that you can restore from those backups!

    I’ve read horror stories about losing or breaking a phone and being locked out of everything because the standard phone backups don’t save the passkeys private keys.

    Personally I’m waiting until Bitwarden supports passkeys and I’ve made damn sure I can restore them from backup.

    • vzq@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      edit-2
      1 year ago

      That’s not how passkeys work. You still have the usual Google account recovery flow.

      Just make sure you have some 2FA backup codes stuffed into a sock drawer somewhere, that your email address and telephone numbers are up to date and you should be ok.

    • Polar@lemmy.ca
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      5
      ·
      1 year ago

      I’ve read horror stories about losing or breaking a phone and being locked out of everything because the standard phone backups don’t save the passkeys private keys.

      This is no different than what we already have. Many people don’t backup their TOTP to any cloud provider, or even themselves, and if their phone breaks, they lose all of their TOTP. And most people don’t save recovery keys (if the service even provides them).

      So ya. Stop fear mongering.