I vibe with this. Does anyone have any examples of where and how any vendor’s dialogs around passkeys might lead people astray? The more feedback, the better.
https://infosec.exchange/@adamshostack/113743707996398149
Adam Shostack :donor: :rebelverified: (@[email protected])

@[email protected] I think the biggest thing is to (a) ensure dialogs are clear about what software is presenting them (b) where it plans to store the key and (c) letting people configure what their preference is for passkey management. Err, “things are”

Infosec Exchange
@rmondello @adamshostack Atlassian 2FA options include “2FA security keys, which can be hardware or software.” Setting up a “software 2FA security key” creates a passkey, but the word “passkey” is completely absent from the whole process and docs, the passkey is used as a second factor after you fill username and password (shitbags), and their tech support people Will tell you they don’t support passkey and will argue that software security keys are a different thing.