[This post was written in collaboration with a young former colleague of mine, although he wishes to remain anonymous.]
Over the last couple of years or so, the FIDO2 protocol (see What is FIDO2) has started to become more widely used. Since “FIDO2”, “U2F”, and “WebAuthN” don’t really roll off the tongue, some marketing genius, probably at Apple, came up with the name “passkey” for the latest incarnation of this technology.
You should re-read What is FIDO2 if needed, but the summary is that this technology uses digital signatures under the hood, while presenting the user an absolutely phishing-proof way to login to sites without having to remember any password.
The problem till now has been that, regardless of what device you used for this purpose, there was no way to create a backup copy without buying more hardware devices. For someone like me, who keeps several copies of his password file (multiple disks, one copy sent to my wife, one to my son, one to my brother, etc)., this was obviously not going to work. (Each yubikey costs between 30-50 USD by the way, but more than that, you’d have to individually register each one on each website, which is a real pain and does not scale at all! Imagine having to go to my brother’s place and retrieve the Yubikey every time I need to register a new website!)
As of a few days ago, that problem has been solved! My favourite password manager, KeePassXC, has released support for “passkeys”. My passkeys (once I start using them) can go into the same KDBX file which currently holds my passwords, and enjoy the same redundancy/availability I described above.
I’ll update this post or add a new one once I start using this.