4 ms·
We wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting. Technically a Passkey is just a multi-device FI
by snagg 4y ago
We wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting.
Technically a Passkey is just a multi-device FIDO credential that is compatible with WebAuthn (which is an official W3C and FIDO spec).
However, vendors implementations of Passkeys/FIDO credentials differ quite widely. The Apple implementation of Passkeys, as an example, doesn't provide attestation information which reduces the ability to do device verification. Similarly, even though it's not technically part of Passkeys, Apple removed the possibility to create device-bound WebAuthn keys which significantly weakens the security guarantees you'd normally get with WebAuthn.
[0]https://www.slashid.dev/blog/passkeys-deepdive/ https://www.slashid.dev/blog/passkeys-deepdive/
- xwowsersx 4y agoThis looks great, thanks for the link
- snagg 4y agoHappy to chat more about it if you'd like!
- PassageNick 4y agoThat's a great article, thanks. In fact, it's a fantastic article. I read it a couple of weeks ago, and learned a lot. Thanks. Apple's changes do degrade security, but I think it is important to note that even with those degradations, Apple passkeys are still many orders of magnitude more secure than passwords.
- snagg 4y agoThank you! 100% agree - realistically, given their scale, the tradeoff made sense. The UI would have been fairly un-intuitive for users had they left the option to do both device-bound keys and passkeys.