Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I do not believe this is true. Passkey is only a 1 user, 1 key system. This means that to login on a second device, the 1. key must be exported from the first device, 2. encrypted, and 3. transferred to the second device. Each device needs a copy of the private key.


You can add multiple passkeys on your Google account today. If a website is dumb enough that they only allow a single passkey per account, they have misunderstood passkeys profoundly.


Google != passkeys. Google may allow multiple keys, but that is outside of what FIDO specifies for passkeys. Here's a source saying that passkeys expect one and only one key:

https://auth0.com/blog/our-take-on-passkeys/

"Passkeys are designed to [...] allow the FIDO credential to roam across multiple devices. This [means that there's ] no need to repeat enrollment on each device [.]"

> If a website is dumb enough that they only allow a single passkey per account

And that's exactly my point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: