4 ms·
I think a per-user blockchain with many user keys and a Merkle root representing current account state, synced individually to websites, would be a superior opt
by Zamicol 3y ago
I think a per-user blockchain with many user keys and a Merkle root representing current account state, synced individually to websites, would be a superior option to "passkeys". Websites would have to track a Merkle root on a per user basis.
User A: Merkle root AA
User B: Merkle root BB
Edit: A problem with passkeys is a one (key) to one (user) relationship, which means device keys must be retrievable and transferred to other devices via encryption. It also means that if any device has weak security, your whole account is vulnerable.
A multikey system would allow each device to have their own key, and an audit trail of what devices are logged into what services.
- rootusrootus 3y ago> A problem with passkeys is a one (key) to one (user) relationship That is untrue. It is a many-to-one relationship.
- Zamicol 3y agoI do not believe that is the case. Do you have a source showing that multiple keys for a single user on per a single service basis is supported?
- ewoodrich 3y agoI currently have 5 passkeys linked to my Google account for 5 separate devices allowing me to login to Google on any of them with the passkey created for that device. Edit: Google also shows when each passkey was last used for each device in an audit trail as you describe.
- deleted 3y ago[deleted]
- Zamicol 3y agoGoogle != passkeys. Google may allow multiple keys, but that is outside of what FIDO specifies for passkeys. Here's a source saying that passkeys expect one and only one key: https://auth0.com/blog/our-take-on-passkeys/ https://auth0.com/blog/our-take-on-passkeys/ "Passkeys are designed to [...] allow the FIDO credential to roam across multiple devices. This [means that there's] no need to repeat enrollment on each device [.]"
- ewoodrich 3y agoNot sure what you mean, I have passkeys enrolled from Apple, Windows and Android devices on my Google account and all trigger the same passkey prompt based on the platform implementation. "Device-bound passkeys that do not support syncing are an option for organizations that require additional proof of provenance of a user’s passkeys". Apple supports what sounds like roaming passkeys but device specific passkeys like you are wanting are already supported by the FIDO spec. I think you're interpreting "no need" here as a if that's a hard requirement. Multiple FIDO hardware keys are already supported on many websites so the idea that the passkey standard mandates a 1:1 relationship doesn't make sense.
- Zamicol 3y agoHow are websites going to implement multi-key user accounts? This is all just left up to implementations?