Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wait

So I genuinely cannot backup my own pass keys?

Like, I cannot say "export to file" and put that on a thumb drive and put that in a safe? Make what copies I want?

What kind of dystopian twilight zone where literally "all your base are belong to Apple" (or google or Ms, pick your poison of "choice") we seem to be sliding into?



> Like, I cannot say "export to file" and put that on a thumb drive and put that in a safe? Make what copies I want?

You can not export to file or store a passkey on a thumb drive.

There have been a couple of claims from various sources that this is coming sometime(tm), but no official word from any of the larger players. I will believe it when I see it.

In addition, if someone does build an Open Source authenticator app that allows you to export and import your keys, there's a capability called hardware attestation that allows login providers to ban authenticators, so there's no guarantee your Open Source authenticator will actually work with every site you want to make an account on.

Think of that like going to log into your bank and being told you can't log in because you're storing your password in Bitwarden instead of the Apple password manager. The current way the spec deals with this risk is by asking very politely for companies to not do that unless they have a really good reason.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: