8 ms·
I like and use fastmail but I'm yet to hear any sort of convincing argument why passkeys are better for me in any way, shape or form than passwords (with a pass
by sho 2y ago
I like and use fastmail but I'm yet to hear any sort of convincing argument why passkeys are better for me in any way, shape or form than passwords (with a password manager)?
- toomuchtodo 2y agohttps://fusionauth.io/blog/why-passkeys-matter https://fusionauth.io/blog/why-passkeys-matter https://coderoasis.com/passkeys-will-replace-passwords/ https://coderoasis.com/passkeys-will-replace-passwords/ https://developer.apple.com/videos/play/wwdc2022/10092/ https://developer.apple.com/videos/play/wwdc2022/10092/ https://arstechnica.com/information-technology/2023/05/passkeys-may-not-be-for-you-but-they-are-safe-and-easy-heres-why/ https://arstechnica.com/information-technology/2023/05/passk... TLDR Replaces secret strings with crypto primitives mostly automatically managed.
- eep_social 2y ago> mostly automatically managed boosters have yet to address this particular elephant to doubters’ satisfaction
- toomuchtodo 2y agoDoubters gonna doubt, it's shipping to hundreds of millions of people today, and their passkeys are backed up to either iCloud Keychain or Google Password Manager (depending on ecosystem). If you have a password manager, that's great! Most people do not, and this is easier for them.
- tomjen3 2y agoYeah it’s easier than ever right until you lose your iPhone and buy an android.
- deleted 2y ago[deleted]
- bscphil 2y agoDo you have examples of a few popular sites that support them? I honestly don't know that I've seen one, unless the Apple / Google / Github / Gitlab "single sign on" links have all quietly switched to using passkeys under the hood (I thought they were all OAuth 2.0). Would be frustrating if so, because it wouldn't provide for custom / hardware implementations of the standard.
- toomuchtodo 2y agohttps://www.theverge.com/2024/7/30/24209395/dashlane-passkey-report-adoption-passwordless-sign-on https://www.theverge.com/2024/7/30/24209395/dashlane-passkey... https://www.theverge.com/2024/5/2/24147030/google-passkey-passwordless-authentication-400-million-accounts https://www.theverge.com/2024/5/2/24147030/google-passkey-pa... https://passkeys-directory.dashlane.com/ https://passkeys-directory.dashlane.com/ https://passkeys.directory/ https://passkeys.directory/
- bscphil 2y agoSeems like the overwhelming majority of the listed sites require you to already have an account, then go to a difficult-to-find URL on a settings page, enroll a passkey, and then you can login with the passkey. So granted, a handful of sites support it, but I have trouble believing the Google number. Maybe that's including people using their device to sign into Google itself? Putting myself in the position of a typical user, passkeys haven't "replaced" passwords until I don't have a password for Home Depot or what have you. Otherwise there's still a password I have to write down or remember somewhere. I'm not even here as a hater - I do like the idea of cryptographic authentication replacing passwords - but I'm just saying I've seen zero real world uptake of this so far.
- nixosbestos 2y agoEr, Google uses Passkeys and yes is an OAuth2/OIDC IdP for federated sign-in. I think you're missing the point though. I can still login to Google and Tailscale without ever typing a single password, trusting my url bar/eyes, sharing any secret material, etc.
- eep_social 2y agoalways disappointed to hear “well it’s good because we already built it this way” as a deflection. you will, of course, do what you like but the flippant attitude is a showcase of why the boosters have failed to bring the doubters along. reassuring to hear that I can further offload my login security to an opaque fortune 500 of my “choice” if, when challenged, one is unwilling to acknowledge the trade offs that indicates that they don’t understand them which suggests that they should not be trusted, in short. forced passkeys are coming and I do not believe that is a good thing.
- yurrzz 2y agoA lot of advertising on this page, but this is 1passwords explanation of the difference. https://1password.com/product/passkeys https://1password.com/product/passkeys
- peppertree 2y agoFaceID.
- rlayton2 2y agoThe article does a pretty good job of making this argument, including your (and my initial!) question about why not to just use password managers.
- athrun 2y agoThe announcement post from Fastmail does a good job at listing the advantages of Passkeys over passwords: replay resistant, database-leak resistant and fishing proof.
- kijin 2y agoPassword managers are phishing resistant. The browser plugin will not offer to autocomplete passwords on an identical-looking punycode domain. A sufficiently long, randomly generated password is also database-leak resistant. Good luck brute-forcing a 128-bit random string, hashed with scrypt or whatever. So the only significant advantage is replay resistance. Which might or might not be a big deal, but let's not overplay the advantages.
- aaomidi 2y agoPasskeys means no secret material traverses the web. This is a huge benefit. There’s no other way to put it. From the admin side this also means significantly simpler database design
- theshrike79 2y agoAre password managers resistant to social engineering? You can copy & paste a password to a "support chat" from the manager. You can't do that with a passkey. The password is only resistant if the one storing it is following best practices, which are NOT enforced and you really can't check for from the outside.
- kijin 2y agoWell if we're talking about social engineering, I don't think it will be difficult to convince the support guy at most companies to disable passkeys on the target account altogether. :(
- theshrike79 2y agoIf you can engineer "the support guy" then you can do a lot more than disable one passkey. I'm talking about engineering on the other side, the person who has the password and uses it to log in. You can't social engineer Miriam from Accounting to give their passkey, you can do it with a password.
- varenc 2y agoBesides what others have said, I think non-tech savvy users get a huge benefit from passkeys. Imagine the people that aren’t already using password managers (probably most people). With passkeys there’s no way they can reuse or leak a password. Passkeys are quite easy to use.
- weikju 2y agoSo far, non-tech-savvyy I know in real life who have interacted with passkeys have been more confused than helped by how they were implemented. Most likely as a result of blindly clicking yes/ok/accept/etc when asked to migrate to passkeys (e.g. on Google).
- tptacek 2y agoPasskeys (and FIDO keys generally) are mutually-authenticating, which makes them phishing resistant. Phishing resistance is enormously important.
- dadrian 2y agoThey're not mutually authenticating, they're origin-bound (making them non-forwardable on the remote side) and channel-bound (meaning the authenticating action is guaranteed to be for the same device as the user action). However, there's no particular reason a FIDO key couldn't sign a login statement to a phishing site---it's just that statement wouldn't then be usable as a valid credential for the true site, regardless of if the signature from the FIDO key was valid or not.
- skybrian 2y agoPasskeys are basically a protocol upgrade for password managers. A limitation is that you have to use a password manager, but the protocol is more secure. If you have a password manager you like, maybe it’s for the best? Maybe use more than one password manager, just in case.
- al_borland 2y agoI have been using a password manager for 16 years, and as much as I always want to use autofill, there are still situations where I need to either copy/paste the password, or reveal the password and type it in. I don’t think we’re at a point where I can 100% trust that the password manager will be able to handle every situation I run into from now until forever, and that’s what passkeys are asking for. I don’t see it.
- aaomidi 2y agoPasskeys are specifically interacting with a pwd manager. Before this, the manager had to try to figure out what’s a password field.
- al_borland 2y agoAnd what happens when I need to login to a device I don’t own, or don’t have/want my personal password manager on? For example, I can’t (and won’t) load my personal password manager on my work computer, but there is 1 site I use my personal account for and had to login when I got a new work laptop a few months ago. Another example is I still bum TurboTax off my dad, since he gets the version where he can do a bunch of returns. To download my data from the bank I need to login on my dad’s computer, and I’m pretty sure even if it was mine the password manager isn’t going to work with TurboTax. Another example I had was needing to login to a site to download and print something on a computer in a business center at a hotel… not something I ever want to make a habit of, but I was in a bind. I could go on. These things come up. I think the idea that a person will only ever need to login on their own computer is unrealistic. That might be the case 99.9% of the time, but not 100%. That 0.1% does need to be accounted for.