4 ms·
AFAIK, you can register your passkeys using your own provider (eg. Bitwarden). I’ve not personally used it too much, but the option is there. The remaining iss
by ratorx 2y ago
AFAIK, you can register your passkeys using your own provider (eg. Bitwarden). I’ve not personally used it too much, but the option is there.
The remaining issue is moving the credentials between providers, which is an annoying limitation. But you can always add a different passkey to the site using the provider you want, so although annoying it is not the end of the world…
The original limitation is similar to the usability of actual physical security keys, which (depending on the setup mode) are deliberately designed such that the private key material is not recoverable. Software based keys don’t HAVE to share the same limitation, but it seems more like a missing feature than attributing malice to the creators of the spec.
- lapcat 2y ago> AFAIK, you can register your passkeys using your own provider (eg. Bitwarden). Why should we even need a third-party provider? Imagine needing a third-party "provider" for your own ssh keys.
- joshuamorton 2y agoDo you use the same SSH keys on multiple devices? I certainly don't. If you need or wanted to (you don't) you'd need some way to sync them across multiple devices securely. When I use passkeys on a single device, the "provider" is the OS, same as with my SSH keys.
- troupo 2y ago> Do you use the same SSH keys on multiple devices? Yes. For example, when upgrading or reinstalling a system > If you need or wanted to (you don't) you'd need some way to sync them across multiple devices securely. `scp -r` > the "provider" is the OS, same as with my SSH keys. And you have full access to ~/.ssh and you can move copy update rename delete them however you like. Without a "Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF)" to move between blackboxes of third-party providers
- joshuamorton 2y ago> And you have full access to ~/.ssh and you can move copy update rename delete them however you like. I think this comes down to me never having wanted to do a copy or move (I create and maintain new keys when I create new devices) which is exactly the same experience i get with a passkey (and is, generally a more secure experience since my keys cannot be exfiltrated since copying them is implicitly verboten).
- Terr_ 2y ago> Do you use the same SSH keys on multiple devices? Assuming you mean client devices, yes, depending on my personal relationship/control of the device. (For servers, the answer is "very yes".) For example, my personal laptop and desktop may have the same private key, and I will backup/restore that same key onto either of them if they are reinstalled or replaced with new hardware. However my work laptop gets its own, so that I can more-easily limit what it can access or cancel it in the future.
- craftkiller 2y ago> Do you use the same SSH keys on multiple devices? Yes. > you'd need some way to sync them across multiple devices securely. I take out my physical keychain and plug in my yubikey. Then, after typing in the password to my yubikey, I can use ssh and pgp until I unplug my yubikey. It is a hell of a lot more secure than storing your ssh keys on disk regardless of whether or not you use a unique key per device. I could lock someone in a room with my computer, my yubikey, and my password, and they still wouldn't be able to copy my ssh key.
- ycombinatrix 2y agopedantic nit: the yubikey is a device so you are arguably using one unique key per device
- craftkiller 2y agoHaha technically true, but I don't think that was the kind of device they were referring to. Even so, it is possible to use the same key on multiple yubikeys. You generate a PGP key on a secure computer and then load that key onto multiple yubikeys. Then you use gpg as your ssh agent. But this is less secure than using keys generated on-device by the yubikey because your private key exists (hopefully temporarily) as a file on the computer where you generated it.
- joshuamorton 2y agoNo this is absolutely what I meant: A passkey and a PGP key function very similarly in this capacity, a passkey for a site can be generated on a yubikey and used across devices in just the same way.
- 0cf8612b2e1e 2y agoI certainly backup my SSH keys. That way if my laptop dies today, I can be up and running tomorrow without anyone else being involved. How do I ensure I can access my accounts if my phone-containing-passkeys is lost/stolen/dies without backups?
- Scion9066 2y agoYou don't. Same as a physical key for your home, you have backups. Whether that's having multiple separate keys/devices registered with your accounts or a single key stored in a password manager, you need to have a fallback plan.
- ratorx 2y agoIf you only want first-party, you can presumably implement the spec yourself and do whatever you want with the data? My example was only to point out that there exist self-hostable passkey providers.