Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thank you. This is helpful, as this is the first example of an actual key export that I've seen. The tiering system is interesting, that could work too.

On the flip-side, backup keys are not a solution for me in this instance. The model being proposed is one where we have hundreds of passkeys in our vaults, one for each service. I don't want to spend time setting up a backup key on every service; I want the ease of use of just hitting "use passkey" on a new site and having it all work. I just also want a 100% reliable backup option that has no dependency on any service, vendor-specific system or anything. Essentially, I want a backup that my grandmother could hand to a local kid with tech skills, and be able to get into my account(s) while sitting together at her computer.



I put the passkeys in a password manager, then lock the password manager with multiple physical Yubikeys, keeping several in secure storage.

This same pattern works for Google/iCloud accounts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: