Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
Bitwarden lets you store passkeys in its vault, which I think is what you’re asking for? It’s mentioned in the post too.
I have some passkeys in my Bitwarden, and my Bitwarden account is protected with a USB + NFC Yubikey.
The experience is inconsistent across phone platforms at the moment, but it works great on computers. On Android, it currently only lets you use a password manager if the passkey is your primary credential for logging into the site. Android doesn’t support passkeys from password managers for 2FA yet.
What you are proposing is no different from using a password and wrapping it in custom transport security to send it to the server. This would result in everyone simply using the same password for all sites.
Bitwarden lets you store passkeys in its vault, which I think is what you’re asking for? It’s mentioned in the post too.
I have some passkeys in my Bitwarden, and my Bitwarden account is protected with a USB + NFC Yubikey.
The experience is inconsistent across phone platforms at the moment, but it works great on computers. On Android, it currently only lets you use a password manager if the passkey is your primary credential for logging into the site. Android doesn’t support passkeys from password managers for 2FA yet.
No. I’m talking about using the password to directly derive the passkey. This would eliminate the need to store them in something like BitWarden.
What you are proposing is no different from using a password and wrapping it in custom transport security to send it to the server. This would result in everyone simply using the same password for all sites.