Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Also, just so I'm clear, there's no requirement to share passkeys. Or even have passkeys enabled on all devices, right?

If I log in to a site from my machine, and set up a passkey, but then log into that site from another machine, it'll just see no passkey present and ask for my password, yes?

A passkey is a local password on a device that could be shared through all the password manager gymnastics, but its not required as I understand it.





That’s true for all accounts that i’ve been using (Google, Apple, Microsoft).

Passkey generated on a device can only change login flow for this one specific device. If you don’t synchronize passkey to other devices or if you do not generate passkey on other device, then login flow is different for other device. You need to enter password.

Imo it would not make any sense if it was different.


I think there are passkeys that can be migrated/synced between devices, and device-bound passkeys that can't. I do save passkeys on my password manager and use them across devices, but I am pretty sure I have had passkeys that I could only use from a specific device. Not sure though, it feels a bit confusing.

Yes, that's right. It might also make sense to generate multiple passkeys for an account. For example, a separate one for logging in from Apple devices.

some sites actually let you use a passkey on another device to login. AWS is one.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: