• arrowMace@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      It’s a false dichotomy to have one or the other. I use passkeys as a quicker and more convenient way to log in to some sites, but I still have passwords in my password manager as a fallback.

      • Scrollone@feddit.it
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Some websites prevent you from using a password if you set up a passkey.

        Pass keys are horrible.

        • Flagstaff@programming.dev
          link
          fedilink
          English
          arrow-up
          4
          ·
          1 day ago

          It seems like what’s actually horrible would be those websites’ implementation. But yeah, I’m definitely sticking with a manager.

      • redjard@reddthat.com
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        1
        ·
        2 days ago

        android doesn’t allow 3rd party apps to use passkeys nor autofill 2fa consistently. For passkeys, you are forced to use google services for it, or loose access, making it pointless. TOTP codes meanwhile can at least be copied and pasted manually from a password manager.

          • redjard@reddthat.com
            link
            fedilink
            English
            arrow-up
            2
            ·
            24 hours ago

            It’s android version dependent. Only 14 and up support 3rd party providers.

            Passkeys are supported on devices that run Android 9 (API level 28) or higher.

            On many devices, Credential Manager stores passkeys to Google Password Manager by default. Users can choose other password managers as its passkey providers in the System Settings on Android 14 or higher.

            Given the slowness of android version rollouts, this will be an issue for a long time.

            I also think supporting older androids is pushing apps to do it the “wrong” way and making it google specific.

            • Zak@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              21 hours ago

              14 and up seems to be about 80% of users, and I suspect there’s a correlation between people who want to use passkeys with a third party password manager and being within two major versions of current.

    • Glitchvid@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Really depends on what you mean by passkey, since it’s actually a fairly vague term for a bundle of technologies.

      I don’t really care for password manager passkeys; just use a password, all it really does is save you from needing to enter a username in a login flow.

      But I’m a big fan of hardware 2fa using non-resident keys (“passkey” lite); I’ll use a regular login flow with a password manager, then the 2FA step with a hardware token. Basically bulletproof (ditto if you secure your PW manager with hw 2fa) and painless.

      • Natanael@infosec.pub
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 day ago

        Even pw synced passkeys at least have the benefits of both being phishing resisting + replay protected, as well as being able to use the TPM chip for extra local protection.

        Hardware keys are logically simpler though