Reorx’s Forge 头像

消息来源频道

Reorx’s Forge

@reorx_share

频道3,130 位成员公开可见0 人在线

A chronicle of my journey in forging my ideas into writings and products. Archive: https://app.shokichan.com/c/tg/reorx_share

成员规模3,130 位成员
在线情况0 人在线
消息总数6,041 条消息
浏览量总数784,746 次浏览

在这个频道里搜索消息……

t.me/reorx_share

今年也是见到很多服务开始提示用户使用 Passkey 登录,可实际使用下来,Passkey 不过是另一个浏览器的「记住密码」罢了,并没有真的像我曾经想象的,用一个独立可控的个人密钥设备授权所有认证。或许 Passkey 已经成为又一个实际使用情况与技术设计意图不符的案例——它的用意是好的,但最终却不过是从一个 vendor-lockin 转换到另一个罢了。
I cannot bring myself to agree to any "switch to passkey" prompt from any device because I have no idea (and too tired to figure out) how and where that key will be stored, how do I deal with different devices, etc. I already have a universal solution for credentials: 1password, which is cross-platform. With Apple's keychain, and I suspect other companies' solutions, passkeys are connected to your account and at best synced between devices from the same manufacturer. But even with Apple, I can't sync stuff between my personal and work computer because they use different Apple IDs, even though the underlying true identity (me) is the same.
Like with many other solutions, the current approach with passkeys is designed for an imaginary "user in vacuum" model each company dreams about, where people are 100% into one ecosystem, forever.
https://news.ycombinator.com/item?id=42548985