Some thoughtful stuff about passkeys and the identity system, includes a few angles I hadn’t thought of: https://lucumr.pocoo.org/2025/9/2/passkeys/
Post
Some thoughtful stuff about passkeys and the identity system, includes a few angles I hadn’t thought of: https://lucumr.pocoo.org/2025/9/2/passkeys/
Plus lots of vendor-specific obfuscatory wainscoting in the UIs.
They are per-device/per-website/per-user asymmetric public/private key pairs with the private one stored on the device and each one only used with one user id on one website, with the public key stored at the service provider for that user on that device.
The details about how they are instantiated or revoked are less clear to me.
If I've got that wrong, please, anyone, correct me.
A space for Bonfire maintainers and contributors to communicate