+ CXF 1.0 format: proposed standard
+ iOS 26 + Android: transfer ships
- CXP protocol: working draft, Oct 2024
- hardware keys: no export, by designA passkey is a password your device invents, never shows you, and refuses to hand to anyone, including you, which is the entire security feature and, as of Thursday, the entire complaint. Three numbers. The FIDO Alliance counts five billion passkeys in use. Microsoft measures a 98 percent sign-in success rate with them, against 32 for passwords. And a post titled I don't like passkeys just spent a day on top of Hacker News with six hundred comments. In three minutes: where they came from, what your browser actually signs, and why un-phishable and un-movable are the same word.
PayPal, Lenovo and a start-up called Nok Nok form the FIDO Alliance to kill the password. 2014, Google and Yubico ship the U2F security key. 2019, WebAuthn becomes a W3C standard. And in 2022 Apple, Google and Microsoft rename it passkeys, because nobody ever bought anything called a discoverable resident credential. The ceremony. At registration your device generates a fresh key pair for that one site. The public key goes to the server; the private key stays in the chip. At sign-in the server sends a random challenge, the device signs it, and the server checks the signature against the public key it stored. There is no secret on the server to leak. The phishing part is one field. Before the device signs, the browser, not the page, writes the real origin into the signed data. A look-alike domain gets a signature for the wrong domain, and the real server rejects it. The user can be fooled; the math cannot.
So where does the private key live? Device-bound means a security key, where it never leaves, and a YubiKey holds a hundred. Synced means iCloud Keychain, Google Password Manager, 1Password or Bitwarden, where the key sits in an end-to-end encrypted vault and follows your account. The site can tell which from a sixteen-byte model id called the AAGUID, and most sites ignore it. So both stories are true. Sign-in is faster and stronger, and the FIDO survey says three in four consumers have one. But a secret you cannot read is un-phishable and un-movable in the same breath: when the phone dies, or a robot bans your Google account, every passkey inside goes with it. Hawksley calls that a perfect fit for a corporation and a poor fit for a person; Nikita Bier calls it magic fairy dust. The fix has a name. FIDO's credential exchange format reached proposed standard, and iOS 26 and Android now move passkeys between managers with it. The protocol beside it is still a working draft, two years in. Hardware keys never export by design, so the official backup is a second hardware key, a recommendation with a price tag.
So, Monday. One: keep a password and an authenticator app on every account until the export works for you; the weakest recovery path is your real security. Two: device-bound means two keys on day one. Three, if you build the login: require a resident key, verify the origin on the server, and stop asking for a passkey from someone who just used one. Verdict, under the hood: needs review. The ceremony shipped. The lifecycle is a working draft.
Verdict: NEEDS REVIEW — The ceremony shipped. The lifecycle is a working draft.
Sources
https://hawksley.dev/blog/i-dont-like-passkeys
https://news.ycombinator.com/item?id=49753211
https://www.w3.org/TR/webauthn-3/
https://passkeys.dev/docs/reference/terms/
https://blog.trailofbits.com/2025/05/14/the-cryptography-behind-passkeys/
https://blog.timcappalli.me/p/passkeys-prf-warning/
https://mastersplinter.work/research/passkey/
https://en.wikipedia.org/wiki/FIDO_Alliance
https://www.w3.org/TR/webauthn-1/
https://news.ycombinator.com/item?id=31643917
https://developer.apple.com/passkeys/
https://security.googleblog.com/2023/05/so-long-passwords-thanks-for-all-phish.html
https://blog.google/technology/safety-security/passkeys-default-google-accounts/
https://blog.1password.com/fido-alliance-import-export-passkeys-draft-specs/
https://blog.google/technology/safety-security/google-passkeys-update-april-2024/
https://www.microsoft.com/en-us/security/blog/2024/12/12/convincing-a-billion-users-to-love-passkeys-ux-design-insights-from-microsoft-to-boost-adoption-and-security/
https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/
https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/
https://fidoalliance.org/specifications-credential-exchange-specifications/download-credential-exchange-specifications/
https://arstechnica.com/security/2025/06/apple-previews-new-import-export-feature-to-make-passkeys-more-interoperable/
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

