Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.
But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.
I broke down how passkeys work, their strengths, and what’s still missing



deleted by creator
If its not fully functional it feels more like a vendor lock in than anything actually useful. Use a Google device but want to change? Oh I’m sorry you have to do all this work first thanks to passkeys.
Some websites are better about it but they can also have support in-fighting over which service works better. Its the Password Manager scenario all over again but worse.
deleted by creator
Yeah now try explaining all of that to tech illiterate family who don’t care beyond “I’ll just use Google Passkey” even if its the worst option.
deleted by creator