frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Coming to Apple OSes: A seamless, secure way to import and export passkeys

https://arstechnica.com/security/2025/06/apple-previews-new-import-export-feature-to-make-passkeys-more-interoperable/
21•01-_-•18h ago

Comments

newscracker•17h ago
> The private key remains bound to the user device, where it can’t be extracted.

So what exactly is being transferred with this new cross platform mechanism? Isn’t it the same private key, except that it’s a direct device-to-device transfer?

This export and import of passkeys also seems to blur the lines between passwords and passkeys a little more. If every device supported a built in password manager that generates a random password on signup with a service, stores it securely and then the platforms implement a secure password export and import mechanism where the CSV/JSON/whatever file is encrypted and kept only in memory during a direct device-to-device transfer, that would be close to this, right?

Other than passkeys being randomly generated for each site (and linked to it) and tied to some kind of biometric authentication, it looks like passwords and passkeys are converging (except for some implementation details).

The biggest advantage (which could also be considered a disadvantage from a different angle) with passwords is that one can use it from any device without having their primary device close by. With passkeys, the primary device must be close by if one wants to authenticate with a service on another device.

The biggest disadvantage with passkeys is that if one’s primary device is lost, they wouldn’t be able to login to services. The recovery process would also have to be the same old personal information check or (ugh) secret questions or a link sent to an email address or (ouch) an OTP by SMS to a new replacement device.

lapcat•16h ago
Passkeys are basically the same as ssh keys. What the big tech corporations have "added" is a walled garden. Apparently you can now transfer from one walled garden to another walled garden, Apple iCloud Keychain to 1Password or Google or whatever, but they completely distrust users and refuse to allow users to get directly to the private keys. In other words, they've added paternalism.

I personally don't want to use any "cloud" syncing service, no matter whose it is. I just want to manage my own credentials and back them up myself, like I do with my passwords. Local-only, with offsite backups controlled only by me, is my principle for almost everything. I don't object to the existence of cloud syncing services, as an option for users, but I do object to the forced paternalism on everyone.

One of the great things about passwords is that they are completely device-independent. You can write a password down on a piece of paper. You can do that with an ssh private key too, by the way. It's the ultimate backup that resists all vendor lock-in.

anon7000•16h ago
Anyone can write a password manager which supports passkeys for iOS, and there are plenty of third party ones that already exist! Passkeys are (technically device independent too.
daft_pink•14h ago
I think the criticism is there is no way for the user to access their own passkeys. For example, if you go into 1password, you cannot export your passkey, you cannot view your passkey.

You’ve essentially walked into a form of vendor lockin without that ever being explained to the user and it looks like they are building a way to move from vendor to vendor, but you never get direct access yourself for whatever reason.

pabs3•1h ago
keepassxc has a passkey implementation that can export passkeys.
diggernet•16h ago
> So what exactly is being transferred with this new cross platform mechanism? Isn’t it the same private key, except that it’s a direct device-to-device transfer?

The sentence you quote is describing passkeys, not this new transfer mechanism. I assume this does transfer the private key.

Oh the other hand, while the article is short on details, it sure sounds like this only supports a move operation, where the passkey is removed from the first device and installed on the second. Which means it'll so nothing for disaster recovery, because they are still assuming your one passkey device will always be present and functional. For example, say your iPhone is smashed and you decide to buy an Android replacement. Nope, sorry, first you need to buy an iPhone to restore from iCloud, then you can transfer to Android.

It really needs to be possible to back up passkeys, no matter how much the advocates say we shouldn't be allowed to do that.

anon7000•16h ago
> Other than passkeys being randomly generated for each site (and linked to it) and tied to some kind of biometric authentication, it looks like passwords and passkeys are converging (except for some implementation details).

The fact that a passkey can only be used with the ONE site it was generated at, that it can encode the identity of the user as well as the password, and that there is a standardized, programmatic way to submit/retrieve a passkey to a website are all huge security upgrades over passwords. So no, they aren’t really converging in the ways that matter.

Syncing, export, whatever, are just implementation details of the platform and aren’t really related to the passkey standards.

Someone could create an iOS password manager for passkeys that stores the private keys in plain text for you to view and write down on paper. Of course, the major apps & platforms don’t do that because it’s not a popular feature (or secure), but anyone can write a password app for iOS

krackers•10h ago
I don't get those benefits: randomly generated password is by definition only going to be usable at the site it was generated for. I'm not sure what it means for a password to "encode my identity", but if it includes device-specific bits then that seems like an anti-feature. And autofill for passwords is mostly good enough as a standardized way to input passwords saved in a password manager.
ghusto•14h ago
Too little, hopefully too late.

I can export to another device, _whilst I still have my current device_? That's only half the story, and a little of the anxiety. The real issue is; what happens when my devices are gone? If I get robbed, I'm not sure they're going to be considerate enough to leave me one of my devices so I can still have access to my passkeys.

pabs3•1h ago
Just add some backup passkeys you store in a safe place, like a Yubikey in a physical safe.

The BBC uses robo-cameras disguised as dung heaps to film wildlife up close

https://old.reddit.com/r/nextfuckinglevel/comments/1k7ggw8/the_bbc_uses_robocameras_disguised_as_dung_heaps/
1•palmfacehn•1m ago•0 comments

Datalog in Rust

https://github.com/frankmcsherry/blog/blob/master/posts/2025-06-03.md
2•Bogdanp•4m ago•0 comments

The long afterlife of a literary classic

https://thecritic.co.uk/the-long-afterlife-of-a-literary-classic/
1•pepys•5m ago•0 comments

Apple WWDC25: Platforms State of the Union [video]

https://developer.apple.com/videos/play/wwdc2025/102/
1•tosh•5m ago•0 comments

Voice-controlled agentic robot with pi0

https://github.com/PathOn-AI/awesome-lerobot/tree/main/control_robot/voice_control_agentic_robot
4•danqing0703•6m ago•1 comments

Associations Between Demographic and Relationship Variables and Sexual Desire

https://www.researchsquare.com/article/rs-6799953/v1
1•mpweiher•6m ago•0 comments

Last fifty years of integer linear programming: Recent practical advances

https://inria.hal.science/hal-04776866v1
1•teleforce•9m ago•0 comments

Google Cloud Incident Report – 2025-06-13

https://status.cloud.google.com/incidents/ow5i3PPK96RduMcb1SsW
1•denysvitali•11m ago•0 comments

A Realtime Multimodal AI Agent Framework with Go/Python/C++/Node Extension SDKs

https://theten.ai/
1•halajohn•16m ago•1 comments

Show HN: A Product to Feature Your Products

https://www.go-publicly.com/
1•Sathish_t•18m ago•1 comments

AI Makes Students Dumb and What We Can Do About It

https://medium.com/@klaudel.b/how-ai-makes-students-dumb-and-what-we-can-do-about-it-eac690db46d5
2•jruohonen•22m ago•1 comments

Great Blue Norther of November 11, 1911

https://en.wikipedia.org/wiki/Great_Blue_Norther_of_November_11,_1911
1•gametorch•26m ago•0 comments

Chatty I/O antipattern (2022)

https://learn.microsoft.com/en-us/azure/architecture/antipatterns/chatty-io/
2•motorest•27m ago•0 comments

ScienceDirect AI

https://www.elsevier.com/products/sciencedirect/sciencedirect-ai
1•jruohonen•35m ago•1 comments

Farewell Economy 7, a Casualty of the Long Wave Switch-Off

https://hackaday.com/2025/04/10/farewell-economy-7-a-casualty-of-the-long-wave-switch-off/
2•austinallegro•36m ago•0 comments

Builder.ai did not "fake AI with 700 engineers"

https://blog.pragmaticengineer.com/builder-ai-did-not-fake-ai/
12•todsacerdoti•37m ago•2 comments

Synthesis of hafnium carbide via one-step selective laser reaction pyrolysis

https://ceramics.onlinelibrary.wiley.com/doi/10.1111/jace.20650
1•PaulHoule•38m ago•1 comments

Lisp Machine

https://en.wikipedia.org/wiki/Lisp_machine
2•doener•39m ago•1 comments

How to Write the Worst Possible Python Code (Humor)

https://effective-programmer.com/how-to-write-the-worst-possible-python-code-8c6e49816e90?sk=d06d4241ce97a51a969fbce67070f8ba
1•naveed125•40m ago•0 comments

The most reliable AI agent that works – where Claude, Gemini, and o3 fail

https://substack.recursal.ai/p/the-worlds-most-reliable-ai-agent
1•djshah•42m ago•0 comments

AI agent startups at Y Combinator’s Spring ’25 Demo Day

https://www.businessinsider.com/y-combinator-yc-demo-day-spring-ai-agent-startups-2025-6
5•aspenmayer•43m ago•2 comments

Roll: Reinforcement Learning Optimization for Large-Scale Learning

https://github.com/alibaba/ROLL
1•robertnishihara•43m ago•0 comments

The Talented Ms. Highsmith

https://yalereview.org/article/working-for-patricia-highsmith
2•Caiero•44m ago•0 comments

How Are Students Using Generative AI in UK Universities?

https://markcarrigan.net/2025/05/30/how-are-students-using-generative-ai-in-uk-universities/
1•jruohonen•45m ago•2 comments

Cure Dolly's Japanese Grammar Lessons

https://kellenok.github.io/cure-script/
2•agnishom•46m ago•0 comments

Show HN: I'm a student built an AI to chat with YouTube videos

https://www.wiyomi.com/explore
2•adrinant•46m ago•0 comments

China Moves Forward on Next-Generation 400 Km/H High-Speed Rail

https://www.newsweek.com/china-high-speed-rail-next-generation-2085191
3•decimalenough•47m ago•0 comments

The z80 technique reveals the source code for Atlassian's 'rovo' AI assistant

https://ghuntley.com/atlassian-rovo-source-code/
1•ghuntley•48m ago•0 comments

Embedding Benchmark for Retrieval

https://huggingface.co/spaces/embedding-benchmark/RTEB
1•fzliu•54m ago•0 comments

New video model Seedance Beat Veo3 is now available for free. Try it now

https://seedance.co
1•gravitywp•56m ago•0 comments