Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
I do not like the idea of password-derived
Passkeys, because then acquiring the password is once again all an attacker needs.
Passkeys work now because the device itself is the second factor, the “something you have”.
It’d essentially be a master password like for BitWarden, but instead of needing an app to store a bunch of generated passwords, the master password could be all you need to authenticate.
This exactly how the flow works with Bitwarden now; I’m not understanding how your system makes any changes other than how the passkey is derived.
In fact, that makes things less secure for two reasons: if attackers learn a master password, they can derive other passkeys from it for other sites even if they cannot access the vault (not possible with current passkeys) and if you want to change your master password, all your derived passkeys become invalid and need to be regenerated.
I do not like the idea of password-derived Passkeys, because then acquiring the password is once again all an attacker needs.
Passkeys work now because the device itself is the second factor, the “something you have”.
This exactly how the flow works with Bitwarden now; I’m not understanding how your system makes any changes other than how the passkey is derived.
In fact, that makes things less secure for two reasons: if attackers learn a master password, they can derive other passkeys from it for other sites even if they cannot access the vault (not possible with current passkeys) and if you want to change your master password, all your derived passkeys become invalid and need to be regenerated.