3 ms·
If someone has code execution in your browser, they can just steal your authentication cookies. They don't need your Passkey. It's true that unsynced/hardware-
by md_ 3y ago
If someone has code execution in your browser, they can just steal your authentication cookies. They don't need your Passkey.
It's true that unsynced/hardware-bound credentials can help mitigate such attacks, but they cannot prevent it. The primary threat model of Passkeys is password theft via phishing, reuse, server-side compromise, etc.
If you want to use a USB security key, you still can--Passkeys do not take away from that. But most people are unwilling to go buy a USB key or carry one around, which is where Passkeys--arguably a bit less secure, but far better than the passwords they replace--are still a great step forward.
- rfoo 3y ago> If you want to use a USB security key, you still can--Passkeys do not take away from that. I can't. Most of services I use do not support using Passkeys + a USB security key as second factor. I'm very happy to use Passkeys (synced with my password manager, just like how I sync my password database now) + a USB security key. Unfortunately, most services force me to use Apple (or Google, Microsoft)-implemented Passkeys which are secured by their hardware devices so that they can also function as a second factor.
- md_ 3y agoI don't think most services are requiring specific vendor attestation for Passkeys. I think most services are requiring authenticators that support user verification. Does your USB security key support uv? E.g. https://www.yubico.com/products/yubikey-bio-series/ https://www.yubico.com/products/yubikey-bio-series/
- rfoo 3y agoGood point, it's not about specific vendor attestation. My Yubikey 5 supports user verification via PIN, but it can only store 25 resident keys :( That's my hardwares' fault.