• Jesus_666@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    4 hours ago

    Passkeys are supposed to be bound to one device and protected by that device’s OS’s secure enclave. If you have a second device you’re supposed to create a second passkey.

    That’s why many sites will flat out refuse to let you create a passkey with a desktop browser since a PC-stored passkey doesn’t fit the security model.

    • Assassassin@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      2
      ·
      3 hours ago

      Yeah, that’s how I understood it to work, as well. I didn’t mention it because I’ve seen a bunch of different implementations that don’t seem to work that way. I didn’t want to speak too much on that specific point, since I don’t have a very thorough understanding of it.