4 ms·
Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mech
by macrael 2y ago
Passkeys can't actually replace passwords, right? I will always need a username and password with a website, then can generate a passkey as a separate auth mechanism, which if I lose, I will recover by setting up again using my username and password? I don't get how we can get to a place where passkeys are all, how do you get a passkey on a new device when you only have passkey auth on some other device enabled?
- arianvanp 2y agoThey are stored in your platform's password manager. So they're available on all the devices you're logged into. If you're enrolling a new device (say you buy a new android phone) you can scan a QR code from your previous phone go log in.
- macrael 2y agoI see, so you can use one device to auth and create a passkey on another
- Filligree 2y ago“My platform”? So, like, the BIOS? What if I want to use both a PC and an iPhone?
- arianvanp 2y agoPlatform as in "ecosystem". iCloud Keychain, Google Password Manager, Bitwarden, 1Password, your Yubikey. Anything that can store passkeys. If you want to use both you simply enroll both your PC and your iPhone. There's nothing stopping you from doing this. You can register multiple passkeys from different providers to the same account. You can also log in to your PC with your iPhone by scanning a QR code. And then afterwards enroll your PC as a secondary passkey.
- nusl 2y agoThis is how I'm using them. Still have a username/password, with a passkey as an additional factor. I use 1Password for passkeys rather than Apple's solution, which enables me to use them wherever I have 1Password.
- bradley13 2y agoThat's not the idea, no. The idea is that - instead of a password - you have a cryptographic key. Like an SSH key. This key is managed for you, so you never have to see it or type it. You ought to be able to either have just a few keys, or else a different key for every service you use. Unfortunately, the big players are trying to force this (really excellent!) idea into platform dependency. They want to store the keys on physical devices, which (a) eliminated portability and (b) restricts the number of keys you can have. If your device fails, you will also be faced with account-recovery problems. Great idea, but the implementations are looking...not great.
- whereismyacc 2y agoWouldn't transferring the keys around just massively increase the attack surface? There's a security reason why we want them stored on-device and never moved, right?
- bradley13 2y agoThe KeepassXC file is encrypted (granted, only with a password). Sure, that file is now on multiple devices, so somewhat more vulnerable. The problem with storing on-device comes when you use multiple devices. I have three devices (PC, laptop and phone) that I use regularly and interchangeably. What am I supposed to do, if the keys are tied to a single device? Worse, what do I do if that device dies, or is stolen?
- shepherdjerred 2y agoThink of all of the password leaks you've heard of. How many were due to syncing password vs password reuse, poor site security (e.g. storing in plaintext, weak encryption, etc.) I'm not saying syncing is 100% secure (nothing is), but for most people it's not the main attack surface to be concerned about.
- skybrian 2y agoBoth iOS and Android sync to other devices in the same ecosystem, so there is at least a limited form of device portability. If you have both, register two passkeys with each account and that's even better, since they back up each other if the vendor somehow deletes your account.
- brabel 2y agoThey can, and hopefully will. To get a new passkey on another device, the provider needs to allow you to prove you have possession of your other device first. They can do that by sending you a one-time code, for example, when you authenticate using your existing device, which you can then type in the new device, and that lets you associate your new device-generated key with your existing account. With iCloud, you don't need event that because Apple can, and does, sync your keychain across all your Apple devices. So as long as you use the same Apple ID on different devices, all passkeys are automatically sync'd. If you lose ALL your passkeys, you may be in trouble and for that reason, it's common that when you register your first passkey, you should also be given a long recovery code which you must keep privately in a very secure physical location (as that will allow anyone who can get it to reset your account). You could say that IS a password, and perhaps you're right, but there's a difference in my mind that's pretty big: you're never supposed to use that "password", nor keep it easily accessible or even anywhere in digital form. Finally, a lot of people in this thread are missing that passkeys prevent phishing, and are basically the only way we know to prevent phishing. And phishing is extremely high in the ranking of security issues we currently have to try to solve. If you know a better solution to phishing than passkeys, please let us know (Passwordd Managers are not that if they allow the clueless user to extract the password and manually enter it anywhere)!
- ezfe 2y agoLong recovery code is definitely a password lol. Needs to just have email recovery and call it a day.
- dogman144 2y agoThere’s more to phishing threat models than strictly credential theft, as you seem to imply. If passkeys are around, phishing will certainly still exist, and shift to dropping malware on endpoints or w/e vs going after logins
- brabel 2y agoI don't think you know what phishing means. By "dropping malware on endpoints" I think you mean having a website serving malware? That's not phishing. For an attack to be "phishing", the website needs to be pretending to be some other website that the user trusts. Passkeys completely prevent the user from logging in to another website than the one they've created an account with. Your attack only works on people who basically "trust any website" at all. For those, yeah there's no salvation.
- shepherdjerred 2y agoIt depends on the implementation. Some sites use it to replace both 2FA and passwords, some use it for just 2FA. > how do you get a passkey on a new device when you only have passkey auth on some other device enabled? You'd use a sync service like a password manager.
- patmorgan23 2y agoPasskeys change nothing about account recovery. The same process for a forgotten password should be followed for a lost passkey.