How can passkeys be protected on machines that don’t have biometrics?
I recently found out that on macs without biometrics (no hardware, or not enrolled by user), that passkeys are still available to create and use.
But there doesn’t seem to be a mechanism that protects them. If I want to use the passwords I have stored on my Mac, I at least would be ask to type my password. But for passkeys, it doesn’t. I suppose it’s because it’s going against the philosophy of passkeys to have anything to do with passwords. But then, it’s just one less barrier against attacks on non biometrics protected systems? Why allow passkeys on systems not protected by biometrics? It just makes a hole in security…
BTW, I do know that biometrics is not bulletproof security. If I have the password on someone’s Mac, I can add my own biometrics to use the passkeys. But for this case. I still need to get the password of the account.