The FIDO Alliance is aware of passkey lock-in, and it’s actively working to address that:

With all relevant operating systems now natively supporting passkeys, companies have been increasingly adopting them as an alternative to passwords. Relying on passkeys minimizes the risk of getting hacked, as users don’t have access to their cryptographic keys, and intercepting them is significantly more challenging. However, those switching between different service providers may prefer traditional passwords, as there’s currently no easy way to import or export passkeys. To minimize the friction separating distinct platforms, the FIDO Alliance is working on a solution that makes moving passkeys between them a breeze.

The FIDO Alliance has published (via Neowin) a working draft encompassing specifications that would make moving passkeys between providers possible. When implemented, users would be able to securely import and export their passkeys, making switching platforms less challenging. Read more of the article.


More

Ars Technica: Now there’s a better way to prevent Facebook account takeovers

Facebook is joining a handful of online services—including Google, Dropbox, GitHub, and Salesforce—in supporting security…

Read More →

American Banker: Why banks should consider taking a page from Facebook on security keys

American Banker poses the question, “If Facebook brings physical security keys using FIDO authentication to…

Read More →

ComputerWeekly: Facebook ups security with FIDO two-factor authentication

ComputerWeekly reports that Facebook is upgrading the login security for its 1.79 billion users by…

Read More →