You understood correctly. Seems like I missed some news on the syncing front.
exu
Do you add separate keys on every device?
If you do, how long does it take you to add a new device?
A sufficiently strong password and additional TOTP should protect you well enough.
I'm thinking of phone recovery, where you're trying to get all your stuff back on a new device.
With a password manager, simply logging in will get you there and until passkeys can be synced automatically just like passwords this will need to be handled somehow.
Good incentive for the provider to fix it or go out of business.
QR codes are good 50% of the time; when you're trying to log in on a pc.
The reverse case is extremely annoying
I remain hopeful. Initially, when Keypass wanted to include a simple export option there was talk of banning them from using Passkeys.
Still, it makes adding new devices much more of a hassle.
Good, certificates should be automated anyways. Much more reliable than the once yearly outages because nobody renewed the thing or forgot some systems.
Until recently I kept (most of) my initial setup and config files in a repo with some hacky bash scripts.
Until recently because I finally replaced the bash mess with Ansible and it's so much better.
This does not scale. I have 400 logins in my Bitwarden account right now.