Hi, this is my first post so please be gentle
I am very interested in using passkeys over conventional usernames and passwords. I have read about how they work and there implementation but have reservations on their use in practice,which I have tried to outline below
My current workflow for laptop, ipad or phone
Open the device using fingerprint, face id, password or pin
Sign in to website or account using bitwarden - which is secured by biometric only or by typing in master password
Depending on the website then type in 2FA code generated on the phone or other device, secured by biometric or password.
Only then can I use the website / account
In the above scenario it would mean that even if someone were to obtain my device pin then they would not be able to go further without biometric, 2fa or password information (which would be different to device pin or password) thus adding another layer of security.
From what I have read, using a passkey would be possible by simply being able to open my device without further verification. As a consequence if someone were to obtain my device password / pin by looking over my shoulder then they would be able to access whatever account / website that was on my device.
If this is indeed true then the security of everything (including getting into bitwarden if itās secured by a passkey) will be entirely dependent on the strength of my device pin or password, which somewhat negates all the cryptography and sophistication that underpins passkeys.
Please tell me that my understanding is wrong.