back

by rdl·2y ago·view on hn ↗
Don't they work pretty portably within Apple iCloud keychain or Google equivalent (but only one)? I think some of the legacy password managers are supporting this as well, although my preferred self-hosted vaultwarden option doesn't yet (bitwarden has support, but I don't think it is in the self hosted version yet, let alone in vaultwarden)

There are ways to set passkeys as non-exportable from device I think but that is not the default.

1 comments
Bound to devices chosen by Apple or Google is device bound.

What does legacy mean to you? The usual meaning of outdated is inapplicable in this case.

Device bound is to a specific piece of hardware (whether it supports reinstallation at some level is debatable but I wouldn't use the term for it; Signal is essentially single-concurrent-device-limited even though it has migration capability, but since it can be exported, it's not truly device bound. Apple, Google keychain lock-in is vendor or maybe account lock-in, not device lock-in. "Non-exportable" keys from a secure enclave make it device bound, although a sufficiently functional reprovisioning process might make that only a technical distinction.

Passwords are "legacy" security technology at this point (in the sense of being outdated and bordering on obsolete, and yet still needing to be supported) -- password managers are tools to manage that legacy technology.

No it’s not. At least that’s not what anybody in the security community means when they say device bound. Device bound implies the key is cryptographically tied to a piece of unique physical hardware.