I just got the update on my phone on Google play, Firefox now supports 3rd party password managers for passkeys (on android 14+). Just tried it, and I got prompted with my 3rd party password manager, so it works!

  • Pasta Dental@sh.itjust.worksOP
    link
    fedilink
    arrow-up
    9
    ·
    2 months ago

    I really like them as a more secure way of logging in, its basically what authentication should have been all along (and weve been doing it all along, with SSH keys!). Its about time we take that private/public key concept and apply it to user accounts

    • Moonrise2473@feddit.it
      link
      fedilink
      arrow-up
      4
      ·
      2 months ago

      main issue for me is that i didn’t see any way to invalidate old passkeys. I tried them in a few websites like ebay but it looks like they are valid forever so if my device is compromised, the attacker has access to my account in perpetuity even if i change the password

      • NaN@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 months ago

        You delete it from your account, that makes it invalid. Just like removing an entry from authorized_keys. If the site does this after changing the password or not is up to them.