The point about poor support for 3rd party managers is so frustrating. Because this is correct, that is the obvious solution for the normal user, but passkey implementations somehow do not know how to deal with it.

Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

And the confusing mechanism hurts there too: I'm always a little bit afraid that i'm somehow more in danger because I keep them in a vault that's shared on all my devices rather than a TPM, because whenever the protocol is explained the "it can't leave your device" part is highlighted as the main source of the security, except.... mine obviously do leave my device, with the vault, so.....

Yet, the Apple + Google implementations will sync passkeys between your devices. "Securely", of course. (I've seen first hand how Apple implements this, and it seems.... sound)

Sites can request hardware-bound tokens, which would block any software based password managers. It's an option in the protocol but one not yet widely utilized.

Which is a problem.

It should not be in the protocol. And I don't trust Apple and Google not to lock it away from me.

I want my own open source manager and if that is attempted I want it to lie about it.

I am torn on that. It seems fine for a corporate site to be sure employees are using their company issued tokens to access company data.

It does not seem fine for any other site to do this.

This may be the only place where it would be good with a software patent: corporate would not mind having to pay 10 usd/user/year, Google would never.

Lying about it may become impossible in the future when you throw hardware key attestation into the mix.

https://developer.android.com/privacy-and-security/security-...

FIDO authenticator attestation is dead for consumer-facing RPs. Apple made the right call and simply refuses to support it outside of MDM environments.

Can we try to play nice now and recognize that other people have diverging, but valid, interests from your own? For example, securing things?

Passkeys are not about securing things.

The entire value proposition, and the reason big sites are pushing them, is they take the user out of the loop of authentication. You are no longer authenticating the user, you're authenticating the users device.

For websites you don't have to worry about cookie theft and dealing with the support load of users needing their accounts reset or dealing with fraud. You can also do some level of attestation to hardware which makes automated account creation more difficult.

For the user it offers no additional benefits. You still have something secret that gets presented to a website to login. Password managers solved this problem. But now for some reason you can't log in when you buy a new laptop.

It is playing nice to criticize things. It's not just "different priorities", passkeys have intentional trade offs which cause them to be "more secure" but in ways that users do not want because it negatively affects them. The intentional trade off made in the name of "more security" makes them wildly inconvenient and risks causing massive lockout. Like removing all the staircases from people's homes and replacing them with climbing walls all in the name of "security". You can't just diffuse that by say "well we want banks to be more secure, we have different priorities."

I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys. If they don't have their phone, or it's dead, or it breaks, or is stolen, they just can't access their account anymore. They have no idea how they work or what they're trading off, nor do they understand that they should have prepared for this scenario ahead of time somehow. Upon telling them "yeah you have to use your phone now that you have a passkey" they all universally say "wtf, that's stupid, I never want to have that happen again, I will never use a passkey again."

Passkeys should never have been built for general audiences, they are a huge mistake, I hope they cease to be relevant and die due to everyday folks realizing they're inconvenient and the "more secure" gains ain't worth it for the usability nightmares.

"I am already seeing my "normie" friends getting locked out of accounts due to not understanding passkeys."

In a weird way this is good news for us. If people are losing passkeys, getting locked out, and incurring non-trivial support costs as a result to the relevant companies, then there's no way those companies will crank down even harder by requiring hardware keys.

As an option, I don't mind it existing for situations like a work environment. Work environments are so much easier because there is a clear line to get my credentials reset, from scratch if necessary, even if I lose everything. The problem is that the consumer authentication case is even harder because it lacks that clear line without also creating a backdoor.

So I insist on centralizing my passkeys into a password manager. I have no passkeys outside of my password manager and will continue to reject them. If it's important enough to slap authentication on, it's important enough for me to not lose it because I couldn't choose where to stick it, which is in a basket that I protect very, very carefully.

Honestly I just don't see how something like Amazon could ever turn on the "require hardware key" feature without blowing their own foot off, or really any consumer-facing service. Everyone loses keys. To a first approximation nobody is going to buy three keys and correctly manage setting up all of them to work with every service. Even if we magically stipulate that all sites support it and they all have some integrated unified approach so that there's no software-side friction at all to register all three at once everywhere, you just get too many people who stuck all three keys on one keychain, people whose houses burned down, people who so successfully stored both backups "securely" that they have no memory of where they are anymore or how to get them back, an endless parade of lost keys. The consumer as a whole is not capable of managing hardware keys.

Given how often my household loses its second car keys for extended periods of time I am not exempting myself from this. My work key lives a much simpler life... it just sits in one place, doing work things. My family would hardly last a month if everyone had to carry around physical keys to log in to things.

Why should I recognize that as valid interest, when it's straight out hostile to me? I know why they are doing that. It doesn't oblige me to accommodate their selfish interests.

So is there a problem with Apple or no?

I'd absolutely never trust Google to manage passwords/passkeys for me, with their habit of irrevocably auto-banning accounts. Apple seems... better? But that's today. That could change, and then you'd be screwed.

You're not limited to a single passkey by the spec or 99% of sites that support them. The limit is arbitrary and typically when a limit exists it's no fewer than 3 (very rarely 1, but I've only seen that once that I can recall).

I generally add three, one for Bitwarden (my actual password manager), and then the OS passkey store (Android/Chrome password manager or iOS/Apple Passwords depending on the device).

I'm not qualified to say yes or no; but I will say that Apple's tends to make design decisions that try to empower the user as much as they can while still being easy to use, and have more or less maintained that position.where as Google, on the other hand, started as "open" and "you can do it all on our platform" to "we're taking away your control and choice little by little, in order to 'protect' you". Oh, and you hear more about Google perma-banning your account for no clear reasons, than Apple...

> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

What setup are you using? Because I don't have that problem on Linux + Firefox at all

Linux, Mac, and Windows (i happen to use all three regularly for work, hobbies, gaming), Firefox + Bitwarden.

It's totally possible there's something specific about my situation, or the way it was set up in the first place that enables this, idk, but somebody else replied saying they have the same experience so it's not just me.

And even if it was just me, it's still clearly something wrong on the provider's implementation, because it should not be possible for software to sidetrack the user into a passkey enrollment flow, when that user logged in with a passkey to open the current session.

I will take a wild guess (based on that you are using firefox) is that you probably have enabled the various don't save cookies, clear sessions on close or other hardened privacy settings that are the source of 99% of problems firefox users encounter, like increased cloudflare captchas .

Could be! I don't recall turning things like those on, I use firefox for features not privacy, and mostly leave stuff like that at their defaults, which I trust Mozilla + uBlock to filter the invasive trackers while leaving actually useful functionality, but it's possible I fiddled with it years ago and forgot.

Some probably kinda strong counterevidence to that though is that this doesn't happen on all sites, only Amazon. I've never been prompted to make a new passkey after passkey login on the 12 other sites that I have passkeys in bitwarden for.

Very strange! Whatever the bug is, I hope Amazon fixes it.

It's quite crazy to just surprise a user with a passkey in any event, even if they get saved and don't reprompt you. Suddenly spawning an OS popup without any explanation, which may or may not try to ask for biometrics, is crazy.

> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

I haaaaaate this. And every time I'm like, "do I not already have one??" Passkey implementation has been half-assed by everyone.

I don't have any issues using Bitwarden as the default password manager on any of my devices, except the occasional Android/Google issue with apps where it opens the Chrome passkey store and doesn't prompt for Bitwarden.

But websites pretty much universally trigger the Bitwarden passkey prompt, or I can bypass via the popup and go to the OS passkey manager.

> Amazon prompts me to create a passkey everytime I log in, even when I logged in with a passkey, because my passkeys live in Bitwarden rather than my OS or browser.

I use 1Password and Amazon does not prompt me like that. However I do have two passkeys for Amazon, one in 1Password and one in Apple Passwords. There's not enough data yet to say if it happens to you because of something not working right between Bitwarden and Amazon, or something about Amazon doesn't work right if you don't have a passkey in your OS passkey store.

Might be worth adding a passkey for Amazon to your OS passkey store and see if the problem goes away. If it does, blame Amazon. If it does not, report it as a possible bug in Bitwarden (altough it still could be an Amazon bug that just happens to mess with Bitwarden but not 1Password).

It's amazon, I have 1password and it always asks me to create another security key