3 ms·
The issue they state isn't password reuse. All the bits and such to generate those passkeys originate on one device... And it's specifically designed for it's
by tehbeard 3y ago
The issue they state isn't password reuse.
All the bits and such to generate those passkeys originate on one device...
And it's specifically designed for it's security, to not allow the key material be removable from that one device...
A device that may end up in the bottom of a canal in Venice...
It's then a case of how do you bootstrap back up to having access?
- Did you remember to spend money on an additional passkey device?
- Did you ensure you don't need the passkey device you lost to access the other device which the passkey syncs with (for the iOS keychain/google whatever options)
- Did you remember at each. and. every. account. you. have. to enroll both your primary and secondary passkeys?
vs.
- You can remember enough to get into email for resets, or there's a note or a thumb drive kept in a drawer that has enough password info (itself possibly password protected) to get you back on your digital feet.
I understand the need for not being able to export from a passkey device... but it massively shifts the paradigm of how users need to operate. And puts all the trust in devices.
- Double_a_92 3y agoI had the same concerns. But I think the idea is to have multiple passkeys on different devices for each account. Also the account recovery process should be the same as if you forgot your password. All I miss now is the possibility to backup / sync the passkeys myself, without having to rely on Apple or Google or whatever.
- Brybry 3y agoAren't "cloud" passkeys multi-device FIDO credentials [1][2] where if you lose all devices with access to your keychain you can use account recovery [3] to get a copy on a new device? So I thought you shouldn't need an additional passkey device or to remember anything special other than account recovery information. Then, optionally/implementation specific(?), when you login with a new device for the first time, with that cloud/multi-device credential, some other shenanigans happen. [4](?) [1] https://media.fidoalliance.org/wp-content/uploads/2022/03/How-FIDO-Addresses-a-Full-Range-of-Use-Cases-March24.pdf https://media.fidoalliance.org/wp-content/uploads/2022/03/Ho... [pages 5-7] [2] https://www.w3.org/TR/webauthn-3/#backup-eligible https://www.w3.org/TR/webauthn-3/#backup-eligible [3] https://support.apple.com/guide/iphone/passkeys-passwords-devices-iph82d6721b2/ios#:~:text=Recover%20your%20iCloud%20Keychain https://support.apple.com/guide/iphone/passkeys-passwords-de... [4] https://www.w3.org/TR/webauthn-3/#sctn-device-publickey-extension https://www.w3.org/TR/webauthn-3/#sctn-device-publickey-exte...
- beej71 3y agoLink 3 was very useful, thank you. The fact that the other three links go to whitepapers and specs is part of the PR problem passkeys have. It's hard to parse for answers to simple questions. Such as: what if I don't want to use Apple any longer and wish to move to another provider?
- ngrilly 3y agoIf we don't want to use Apple any longer, then I'm afraid we have to manually recreate create and register new passkeys for every service we use... At least, that's my understanding. I hope they fix this with a "portability" solution.