this post was submitted on 14 Feb 2024
263 points (88.8% liked)

Technology

59534 readers
3199 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Passkeys: how do they work? No, like, seriously. It’s clear that the industry is increasingly betting on passkeys as a replacement for passwords, a way to use the internet that is both more secure and more user-friendly. But for all that upside, it’s not always clear how we, the normal human users, are supposed to use passkeys. You’re telling me it’s just a thing... that lives on my phone? What if I lose my phone? What if you steal my phone?

you are viewing a single comment's thread
view the rest of the comments
[–] Heavybell@lemmy.world 158 points 9 months ago (36 children)

Until someone can explain to me how I can transfer, manage and control my passkeys without syncing them to some hostile corporation's cloud infrastructure, passkeys will remain a super hard sell for me.

[–] TreeGhost@lemm.ee 37 points 9 months ago (4 children)

You can use Bitwarden to store passkeys. Not sure if the self hosted solution has support for it yet though.

[–] sailingbythelee@lemmy.world 23 points 9 months ago (1 children)

I must admit that, despite reading about passkeys a bit, I still don't understand the actual practicalities. I seem to recall that Bitwarden can store keys, but can't generate them. If that's true, who generates the passkey?

[–] Spotlight7573@lemmy.world 22 points 9 months ago (1 children)

Bitwarden can both generate and store them in the browser extension. It can also use them through the browser extension but it can't yet use them through the mobile apps (they're working on it).

[–] Zeroc00l@sh.itjust.works 1 points 9 months ago (1 children)

Bitwarden pro right? ($10 for the year, totally worth it). My mobile app can create/use them already too.

[–] Spotlight7573@lemmy.world 5 points 9 months ago

Don't need the premium version of Bitwarden to use passkeys. The free version works.

That said, $10 per year is not a big cost to support the company storing your vault and developing the apps.

[–] TheOneCurly@lemm.ee 10 points 9 months ago

Vaultwarden does at least, I've been using it with passkeys for the last couple months and it's been great.

[–] subtext@lemmy.world 2 points 9 months ago (1 children)

2024.1.2 released with self-hosted server passkey support.

TBH though I would not trust myself to self host my keys to my digital life when the alternative is $40/year for the whole family. You may have a different perspective though.

[–] csolisr@communities.azkware.net 2 points 9 months ago

You can just use something like YunoHost, and synchronize weekly encrypted backups via Nextcloud or Syncthing to all of your computers. That way, if your server ends up busted for whatever reason, you can just restore it elsewhere and go back to business

[–] csolisr@communities.azkware.net 2 points 9 months ago

VaultWarden user here - yes you can now use your own self-hosted server to store passkeys and that's a gigantic game-changer. Just install the BitWarden add-on on a recent version of Firefox and voilà

load more comments (31 replies)