Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

  • lukaro@lemmy.zip
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 hours ago

    All I know is a few months back someone setup a passkey on a shared google account at my job and now nobody but knows what the password for our email is. I can use the passkey to sign in with my phone, but only I can do that.

    • sentientRant@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      I think Google accounts are made usually for single user and thus passkeys. But may be you can try going to the share Google accounts security and there’s an option skip password when possible. Disable it… May be it might work. I’m not sure tough.