If you are looking for something like a password manager but for passkeys, I would like to plug my own product Bulwark Passkey (https://bulwark.id). It allows you to sync accounts across devices and is entirely open source.
Overall, I think what passkeys need right now is more flexibility. Nobody is going to switch to passkeys if they are locked to their Apple account, for example.
Thank you for having an honest FAQ, especially about keys not being backed by hardware and its implications. Some competitors implementing a comparable mechanism have been very quiet about it and have severely undermined my trust in them. Hopefully we'll see OS and hardware vendors provide APIs so that third party passkey managers can leverage secure hardware in the future.
Yeah, trust is a big thing for me when it comes to security software, so I wanted to be upfront about what the software is good/bad against. I personally think that moving away from passwords is worth it, even if the credentials aren't stored in silicon, but I can appreciate those people who want their keys stored as securely as possible.
Admittedly I've done a little research, but every time I read about I don't understand how passkeys/fido/yubikey works. Is it guaranteed that all the services I use support passkey/yubikey/fido? If not, what should I do? Have some of services in a passkey/fido/yubikey (like yours) and the remaining in Bitwarden or other password manager?
Can someone ELI5 how this works? I went to fidoalliance.org and honestly, I didn't understand a thing. I still don't understand Yubikey and its MFA, it feels so cumbersome and huge PITA to do it every-time. Am I missing something? My workflow now is: CMD+SHIFT+L, enter master-password once and that's it for the current OSX login session. Will Passkey or FIDO or Yubikey improve this speed of interaction?
Passkeys are still pretty new, and only some websites support them so far, though many are adding support right now. You can take a look at https://passkeys.directory for a list of major websites that support it.
At least with Bulwark Passkey, its a separate app that you only have to log into once when you open it. Then, when logging into a website, you hit Approve on the app and it should just work. Speedwise, it should be about similar to an optimized password flow, but security-wise it will be much better since you can't phish passwords from it.
Overall, I think what passkeys need right now is more flexibility. Nobody is going to switch to passkeys if they are locked to their Apple account, for example.