tl;dr: passkeys, as proposed now, will fill up existing fido2/webauthn authenticators if the feature becomes widespread enough. this is because the feature of “passkeys” actually refer to resident keys, which most authenticators today can only store a limited amount of (some, none at all!). preventing this will require changes to either webauth, fido, or passkey libraries.

  • It seems like if your hardware can’t hold all your passkeys you could just store one for your password manager and then the rest of the passkeys that didn’t fit can come from the password manager. Or I barely understand how this stuff works and that’s not feasible? I haven’t used passkeys yet and my first yubikeys arrive tomorrow.