5 ms·
I think I'm a tech guy and know my fields. I still have no real clue how passkeys work, how it is better, what it really is. When your security feature is not
by myspy 2y ago
I think I'm a tech guy and know my fields. I still have no real clue how passkeys work, how it is better, what it really is.
When your security feature is not as simple as - remember a name and a password and store it somewhere safe - it doesn't work.
Something about keys that are on devices. But what happens when I use a phone and a pc? How to get access then? Do I need a User/PW for the first time? Or do I need one of those keys I have to plug into the device first?
- 4ad 2y agoPasskeys are exactly like SSH keys. You should use them exactly like you use SSH keys.
- vaylian 2y agoWhat about storing/backupping/managing passkeys versus SSH keys?
- 4ad 2y agoIt's the same, you should not store or backup SSH Keys.
- redeeman 2y agoand then the real world comes knocking
- carstenhag 2y agoSo I should get locked out of all services when my device breaks?
- dwattttt 2y agoYou should produce a key per device, and produce a backup key that is safely stored & not used anywhere. You can recover if you lose all devices via your break-glass backup key, and you limit the blast radius of "my key got stolen" from rotating all your keys to just a single device (or maybe the more likely "I screwed up and pushed my key somewhere public")
- crote 2y ago... which is completely nonviable if you connect to more than a single service. I agree that you should use a different key per device, but when you connect to over a dozen different services/machines it quickly starts to become a serious chore to add another key. Have fun spending an hour enrolling your new device - provided you can even remember every single usage it should be enrolled with.
- 4ad 2y agoSSH certificates solve this issue. AFAIK there is no equivalent for Passkeys.
- crote 2y agoUnfortunately SSH certificates have really poor uptake in practice, and it's essentially unheard of to have a personal CA instead of a per-company CA. But yes, having a single long-living "primary key" everyone can trust which you'd use to generate short-living per-device "secondary keys" would indeed be the ideal solution.
- red_trumpet 2y agoI have to store them on my disc, in order to use them tomorrow.
- Spunkie 2y agoOddly enough you don't. We've been storing our ssh keys(ed25519-sk) as resident keys for years now without issue. So basically we've been storing ssh keys directly on yubikeys the same way passkeys are stored since before passkeys were a thing. It seemed a clearly superior option compared to letting ssh private keys roam around on random computers.
- tsimionescu 2y agoSure, but then limits you to a handful of keys. The WebAuthn people don't like this, they want one key per service, so basically YubiKeys no longer really work with WebAuthn (unless you're fine with only ever using a max of 25 services).
- fellerts 2y agoCan you elaborate on this? Why not?
- tux3 2y ago"Exactly" is under a lot of strain here. SSH is nice because you don't have to think about it. Your private key sits in your .ssh folder, and then everything is transparent. You _can_ put an SSH key in a smartcard if you want, but you have to opt-in to this kind of pain. And even if you do, almost all SSH servers will support that login method without issue. Passkeys don't sit in your .passkey folder. Your browser doesn't look for passkeys in a standard folder at all. You don't just do passkey-keygen like you would ssh-keygen and forget about it. Websites might support various combinations of FIDO/U2F/TOTP security keys, your USB security key might support various combination of FIDO2/CTAP/WebAuthn, and the user will be left confused what any of this mess means, why there are so many competing standards, and why they're asked to scan a QR code when they plug in their dongle, and it doesn't just work at all.
- bradley13 2y agoPasskeys ought to be exactly like SSH keys. Unfortunately, they are not. The attempts to restrict when and how they are stored, and how you can access them - those are going to cause a lot of pain and confusion. I have all of my SSH keys stored in KeepassXC, which (imho) is a lot more secure than having them hang around in my .ssh directory. Open KeepassXC, and the keys are available. Close it, and they're gone. Synchronizing the KeepassXC-file across devices means that I have access to the keys on all of my devices. The big companies pushing passkeys are trying very hard to prevent this kind of convenience.
- brabel 2y agoThey shouldn't be exactly like SSH keys. With SSH keys, you can go and copy/paste your private keys on a scammer's website because they asked you nicely. People will totally do it as they don't understand what they're doing. The main thing with passkeys, and key dongles in general, is that you simply can't do that as the keys are inaccessible and you can only prove possession of a key when asked by a domain you've explicitly registered with (the proof-of-possession is never sent to any other domain than that which you registered with). What OP says is that opens the possibility for key providers to lock-in users, as that seems like an unavoidable side-effect of the legitimate goal of preventing phishing (phishing is the biggest security issue today, to increase security means making phishing impossible, so I still support passkeys as the best solution for that).
- cyborgx7 2y agoIf they are exactly like SSH keys, then why not just keep using SSH keys. Clearly, there is something else to them.
- whereismyacc 2y agoSSH keys are clearly not a feasible authentication method for non-technical users. Passkeys are here to replace passwords, not ssh keys.
- cyborgx7 2y agoI understand this, but the person who responded said Passkeys are exactly the same as SSH and used the same, when asked what they are. If that was true, then we would just teach non-technical users to use SSH Keys.
- planede 2y agoFor me that means having multiple keys in `authorized_keys` for the same user and never transferring private keys between devices. From what I gathered from the discussion here, this is not a given.
- nottorp 2y agoSo how can i scp my passkey to another machine?
- landmass 2y agoWhy would you want to? Just create a new passkey on the other machine. If you're saving them in a password manager, just create a new entry, "Another Machine's Passkey."